An API, two CLIs and a tunnel to your laptop
Everything the dashboard does goes through a REST API. The same API is what the command-line tools use.
The surface
REST API
Routes under /api cover workflows, versions, executions, triggers, webhooks, secrets, API keys, organizations, notifications, analytics, AI and the marketplace.
API keys
Keys start with kp_, are shown once and are stored only as a hash with their last four characters. A key can carry an expiry in days.
Incoming webhooks
A workflow's webhook URL accepts any HTTP method. Credential headers such as Authorization and Cookie are masked before a delivery is stored. You can send a test delivery and replay a stored one.
Rate limits
Each plan has a daily execution limit, and each workflow can carry its own cap on executions per minute. Past the cap a webhook is refused with an error.
Signed deliveries out
The HTTP Request node and the webhook failure alert can sign the payload with HMAC-SHA256 in an X-Kolap-Signature header, so the receiver can verify it.
Export and import
A workflow exports as JSON and imports from JSON. Versions can be published and rolled back through the API too.
Two command-line tools
The kolap CLI
A small Bun tool: list workflows, run one with a JSON payload, read the last executions and open the dev tunnel. The key and API URL live in ~/.kolap/config.json.
kolap config set api-key kp_...
kolap list
kolap run wf_01HZ --data '{"event":"deploy"}'
kolap logs wf_01HZ
kolap dev --port 3000The Go CLI
A standalone Go binary that covers every /api resource: auth, workflows, versions, executions, triggers, webhooks, the dev tunnel, API keys, secrets, organizations, billing, notifications, analytics, AI, marketplace and OAuth apps. It shares the same config file.
Dev tunnel
Point a third-party webhook at a public Kolap URL and have kolap dev forward each request to a port on your machine. A user can hold at most five active tunnels, each tunnel expires after four hours and each one is rate limited.