Skip to main content
Mythos

Internal Agent API is the REST surface behind 📝MythOS MCP — the same authenticated endpoints and the same key, reachable directly over HTTP for scripts and agents that don't speak MCP. It exists because not every integration is an MCP client; sometimes a cron job or a shell script just needs to curl an endpoint. It's for developers writing custom scripts, automations, or non-MCP agent integrations against a MythOS library.

Key Capabilities

  • One key, two access modes — the same mtk_* API key authenticates both the REST endpoints and the MCP server, which is itself a thin protocol wrapper around this same API
  • Endpoint coverage — the OpenAPI spec inventories every internal route and HTTP method, including agent, session, service, and public operations.
  • Newsletter endpoints are Oracle-gated — listing, adding, updating, and removing subscribers, plus topics and audience stats, all require an Oracle subscription and return NEWSLETTER_NOT_ENTITLED otherwise. None of them send email.
  • Cross-library access — a granted viewer/editor/manager role can authorize an agent to act on a library it doesn't own
  • Rate limited — per key, by plan: 200 requests per minute on Scholar and 500 on Oracle (API keys require one of them); community endpoints have their own separate limits
  • Community calendars are fully reachable — list, read, create, update, cancel, the steward review queue, review decisions, RSVPs, guest decisions, and event guest links. Writes that could clobber a concurrent edit carry expectedUpdatedAt, read from the single-event endpoint rather than the month listing, which does not return one. Community events can be deleted, not only cancelled: DELETE on a community event removes the whole event and all its dates and needs the event's expectedUpdatedAt; to call off one date or a whole series while keeping RSVPs and guest records, use the cancel endpoint. Standalone creator events have no DELETE.
  • Images are uploaded first, then attached — the upload endpoint stores the bytes and returns a URL. Every field that holds an image, including an event flyer, a community avatar, and a collection cover, accepts only a URL that resolves back to a confirmed upload owned by the caller, so a URL from anywhere else is refused. The two steps retry independently, which is why the write carries a URL rather than the file.

Getting Started

  1. Go to Settings → API (requires Scholar or Oracle) and generate a key
  2. Call an agent-key endpoint with an x-mythos-key header set to your key. Before a write (POST, PUT, PATCH, DELETE), call GET /api/internal/augmentation once, then send the contextSessionId it returns in an x-mythos-context header; the session lasts 24 hours. Session, service, and public endpoints declare their own authentication in the spec.
  3. Check the OpenAPI spec for each endpoint's authentication, access restrictions, and request/response shapes.

FAQ

  • Do I need to use MCP to use this? No — any HTTP client works. MCP is a convenience layer for AI clients; the REST API underneath is available directly.
  • Is this gated to a plan tier? Yes — generating an API key requires Scholar or Oracle.
  • How many keys can I have? Up to 10 active keys per account.
  • What happens if I exceed the rate limit? Requests are rejected until the per-minute window resets; the limit is per key, not per account.

Contexts

Created with 💜 by One Inc | Copyright 2026