---
title: "Kolap for developers: API, webhooks, CLI, dev tunnel"
description: "Kolap has a REST API under /api, API keys, signed webhook deliveries, two command-line tools and a tunnel that forwards webhooks to localhost."
image: "https://kolap.org/og-image.png"
---

# An API, two CLIs and a tunnel to your laptop

Everything the dashboard does goes through a REST API. The same API is what the command-line tools use.

[Talk to the founder on WhatsApp](https://wa.me/5548992091242?text=Hi%2C%20I%20saw%20Kolap%20%28kolap.org%29%20and%20I%20would%20like%20to%20talk%20about%20early%20access.%20Section%3A%20page-header.)

## The surface

### REST API

Routes under `/api` cover workflows, versions, executions, triggers, webhooks, secrets, API keys, organizations, notifications, analytics, AI and the marketplace.

### API keys

Keys start with `kp_`, are shown once and are stored only as a hash with their last four characters. A key can carry an expiry in days.

### Incoming webhooks

A workflow's webhook URL accepts any HTTP method. Credential headers such as `Authorization` and `Cookie` are masked before a delivery is stored. You can send a test delivery and replay a stored one.

### Rate limits

Each plan has a daily execution limit, and each workflow can carry its own cap on executions per minute. Past the cap a webhook is refused with an error.

### Signed deliveries out

The HTTP Request node and the webhook failure alert can sign the payload with HMAC-SHA256 in an `X-Kolap-Signature` header, so the receiver can verify it.

### Export and import

A workflow exports as JSON and imports from JSON. Versions can be published and rolled back through the API too.

## Two command-line tools

### The kolap CLI

A small Bun tool: list workflows, run one with a JSON payload, read the last executions and open the dev tunnel. The key and API URL live in `~/.kolap/config.json`.

```
kolap config set api-key kp_...
kolap list
kolap run wf_01HZ --data '{"event":"deploy"}'
kolap logs wf_01HZ
kolap dev --port 3000
```

### The Go CLI

A standalone Go binary that covers every `/api` resource: auth, workflows, versions, executions, triggers, webhooks, the dev tunnel, API keys, secrets, organizations, billing, notifications, analytics, AI, marketplace and OAuth apps. It shares the same config file.

## Dev tunnel

Point a third-party webhook at a public Kolap URL and have `kolap dev` forward each request to a port on your machine. A user can hold at most five active tunnels, each tunnel expires after four hours and each one is rate limited.
