The SLOE OS ability layer. Each ability is one operation: send its input, get its result. Calls are validated against the ability’s schema, attributed to the tenant your credential belongs to, and audited. 79 abilities.
Quickstart
One request per ability
01 · Authenticate
Every ability call carries a Bearer key. Keys are issued per tenant and scoped to a list of abilities. The tenant a call acts for comes from the key: a context.tenantId is honoured only for a key allowed to address sub-tenants, and then nests under the key's own tenant.
02 · Call
POST /v1/abilities/<id> with { "input": … }. The input schema for each ability is on its page.
curl-X POST https://substrate.sloelabs.com/v1/abilities/key.inspect \-H"Authorization: Bearer $SLOE_API_KEY"\-H'Content-Type: application/json'\-d'{"input":{}}'
03 · Read the envelope
Results are nested under result. Failures carry ok: false and a message.
{"ok":true,"ability":"key.inspect","result":{ ... },"duration":2}{"ok":false,"error":"ability not in token scope","ability":"lead.create"}
Status
Meaning
400
Missing input, or input that fails the ability’s schema. details[] names the field.
401
No key, or a key the substrate does not recognise.
403
A valid key whose scope does not include this ability.
404
No ability has this id.
429
Rate limited per key. retryAfterMs says when.
Same abilities over MCP
Hosts that speak MCP connect to /mcp with the same key. Tools are listed per key scope.