Three APIs: the OpenAI-compatible inference endpoint your end users hit, the management REST API the console uses, and the agent enrollment protocol Hux speaks.
Standard OpenAI v1 surface. Hits your fleet directly, never our cloud.
POST https://your-gateway/v1/chat/completions
Authorization: Bearer sk_…
Content-Type: application/json
{
"model": "llama-3.2-1b",
"messages": [{"role":"user","content":"…"}],
"stream": true,
"max_tokens": 200
}
The model field accepts either the model's display name (e.g. google/gemma-3-1b-it) or its slugified routing key (google-gemma-3-1b-it). Hux normalises both. The /api/v1/* path also works for OpenAI client SDKs that prepend it.
JSON over HTTPS, bearer-auth with your console session token. Multi-tenant, RLS-isolated by org.
GET /v1/fleets · POST /v1/fleets · PUT /v1/fleets/{id} · DELETE /v1/fleets/{id}GET /v1/api-keys · POST /v1/api-keys · PUT /v1/api-keys/{id}GET /v1/consumer-groups · POST /v1/consumer-groups · PUT /v1/consumer-groups/{id}GET /v1/budgets · POST /v1/budgetsGET /v1/models · POST /v1/models · POST /v1/models/{id}/replicasGET /v1/nodesGET /v1/audit-eventsThe protocol Hux uses to talk to Kan. You usually don't care about this — the installer handles it. Documented for operators rolling their own deployment automation.
POST /v1/agent/enroll — first-boot. Returns node_id, fleet_id, public_address.POST /v1/agent/heartbeat — every 15s. Reports liveness + applied revision.GET /v1/agent/apisix-config — pulls the rendered apisix.yaml. ETag-based 304s.GET /v1/agent/keyauth-map?since=N — pulls API key + ACL + budget delta.POST /v1/agent/usage — batches usage events.