Management API
Everything the dashboard can do, over HTTP: the inbox, customers, the knowledge base, signals, the agent’s settings, and the numbers. Server to server only, and no CORS headers are sent.
Two credentials open it. MEDIAN_KEY acts as the organization and can do anything an admin can, except send invitations and change members. An MCP OAuth access token acts as the teammate who approved it, with that person’s role checked on every request.
Ids are strings. Pass them back exactly as you received them; an id that is not yours reads as not found.
https://api.median.sh/v1Account
Who a token is, and the setup acts: organizations and keys.
- GETWho am I
/me - POSTCreate an organization
/organizations - POSTSwitch organizations
/me/organization - GETList keys
/keys - POSTCreate a key
/keys - DELETERevoke a key
/keys/{id}
Conversations
The inbox: read threads, reply, and move conversations along.
- GETList conversations
/conversations - GETGet a conversation
/conversations/{id} - DELETEDelete a conversation
/conversations/{id} - PATCHUpdate a conversation
/conversations/{id} - POSTReply as the team
/conversations/{id}/messages - POSTAdd a note
/conversations/{id}/notes
Tool approvals
High risk tool calls waiting on a person, and tools run by hand.
- GETList runnable tools
/conversations/{id}/tools - POSTRun a tool
/conversations/{id}/tools/run - GETList tools
/tools - POSTSync tool endpoints
/tools/sync - POSTTest a tool
/tools/{name}/test - GETList approvals
/tool-approvals - GETGet an approval
/tool-approvals/{id} - POSTApprove a tool call
/tool-approvals/{id}/approve - POSTDeny a tool call
/tool-approvals/{id}/deny - PATCHSwitch a tool
/tools/{name} - DELETERemove a tool endpoint
/tool-endpoints/{id}
Tool suggestions
Tools the agent went without, each written up as a brief.
- GETList tool suggestions
/tool-suggestions - POSTMark a suggestion built
/tool-suggestions/{id}/built - POSTDismiss a suggestion
/tool-suggestions/{id}/dismiss
Customers
Everyone who has written in, and what is known about each.
- GETList customers
/customers - GETGet a customer
/customers/{id} - DELETEDelete a customer
/customers/{id} - POSTRefresh the profile
/customers/{id}/refresh-profile - POSTReach out
/customers/{id}/reach-out - DELETEDelete a fact
/customers/{id}/facts/{factId}
Knowledge
The agent’s library: documents, folders, the review queue, and crawls.
- GETGet the library
/knowledge - GETSearch documents
/knowledge/search - POSTWrite a document
/knowledge/documents - GETGet a document
/knowledge/documents/{id} - DELETEDelete a document
/knowledge/documents/{id} - PATCHEdit a document
/knowledge/documents/{id} - POSTMove a document
/knowledge/documents/{id}/move - POSTRetry indexing
/knowledge/documents/{id}/retry - POSTSync external sources
/knowledge/sync - POSTCreate a folder
/knowledge/folders - DELETEDelete a folder
/knowledge/folders/{id} - PATCHUpdate a folder
/knowledge/folders/{id} - POSTMove a folder
/knowledge/folders/{id}/move - GETList suggestions
/knowledge/suggestions - POSTApprove a suggestion
/knowledge/suggestions/{id}/approve - POSTDismiss a suggestion
/knowledge/suggestions/{id}/dismiss - GETList crawls
/knowledge/crawls - POSTStart a crawl
/knowledge/crawls - DELETERemove a crawl
/knowledge/crawls/{id}
Signals
Bugs and suggestions customers reported, and their trackers.
- GETList signals
/signals - POSTFile a signal
/signals - GETGet a signal
/signals/{id} - DELETEDelete a signal
/signals/{id} - PATCHUpdate a signal
/signals/{id} - POSTMerge a duplicate
/signals/{id}/merge - POSTAccept a signal
/signals/{id}/accept - POSTApply a commit
/signals/commits/{id}/apply - POSTDismiss a commit
/signals/commits/{id}/dismiss
Feedback
Raw notes from anywhere, read and placed on the signal lists.
Tasks
The board work is tracked on: its columns, the requests waiting on a decision, and how it is wired up.
- GETList tasks
/tasks - POSTCreate a task
/tasks - GETList requests
/tasks/requests - POSTPut a request on the board
/tasks/requests/{id} - GETGet board settings
/tasks/settings - PATCHUpdate board settings
/tasks/settings - GETGet a task
/tasks/{task} - DELETEDelete a task
/tasks/{task} - PATCHUpdate a task
/tasks/{task} - POSTDecline a request
/tasks/{task}/decline
Integrations
Email, Slack, Discord, GitHub, Notion, Linear: everything after the consent screen.
- GETEverything connected
/integrations - PATCHSwitch email support
/integrations/email - PATCHPoint the Slack mirror
/integrations/slack - PATCHSet up the Discord side
/integrations/discord - PATCHSet the Linear team
/integrations/linear - POSTSet the issue repository
/integrations/issue-repo - DELETEStop opening issues
/integrations/issue-repo - POSTWatch a repository's commits
/integrations/commit-repos - DELETEStop reading commits
/integrations/commit-repos/{owner}/{repo} - POSTMirror a repository
/integrations/repos - DELETEStop mirroring a repository
/integrations/repos/{owner}/{repo} - PATCHSet the published address
/integrations/repos/{owner}/{repo}
Site
How the public site looks.
- GETGet the site's appearance
/site/appearance - PATCHChange the site's appearance
/site/appearance - GETGet the custom domain
/site/domain - POSTConnect a custom domain
/site/domain - DELETERemove the custom domain
/site/domain - POSTCheck the custom domain now
/site/domain/check - GETGet how visitors sign in
/site/sign-in - PATCHChange how visitors sign in
/site/sign-in
Organization
The organization, its members, and invitations.
- GETGet the organization
/organization - PATCHRename the organization
/organization - GETList members
/members - DELETERemove a member
/members/{userId} - PATCHChange somebody's role
/members/{userId} - GETList invites
/invites - POSTInvite somebody
/invites - DELETERevoke an invite
/invites/{id}
Agent
The AI agent’s name, personality, and autonomy switches.
Webhooks
Where the organization asked to be told what happened.
- GETList webhooks
/webhooks - POSTAdd a webhook
/webhooks - DELETERemove a webhook
/webhooks/{id} - PATCHUpdate a webhook
/webhooks/{id}
Analytics
The dashboard’s numbers and the analytics page’s charts.
- GETGet the overview
/analytics/overview - GETConversation volume
/analytics/conversations - GETSatisfaction
/analytics/satisfaction - GETSignal trends
/analytics/signals - GETTeam activity
/analytics/activity - GETKnowledge coverage
/analytics/knowledge - POSTExplore any dataset
/analytics/explore - GETSpend and model calls
/analytics/billing - POSTList the rows a query matched
/analytics/records - GETDescribe a dataset
/analytics/datasets/{dataset}
Billing
API allowances, usage, invoices and the activity log.
- GETRead the effective API allowance
/billing/limits - GETRead the plan and credits
/billing/overview - GETList invoices
/billing/invoices - GETRead usage history
/billing/usage - GETRead the activity log
/logs - GETRead one log entry
/logs/{id}
Call
Any method of the MCP client, by name, over HTTP.
Docs
Median’s own documentation, searched and read.