Get the infrastructure overview
const url = 'https://api.aletheia-ops.com/api/v1/overview';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://api.aletheia-ops.com/api/v1/overview \ --header 'Authorization: Bearer <token>'Authorizations
Section titled “Authorizations”Responses
Section titled “Responses”OK
The overview landing response — onboarding stage, inventory freshness, and one entry per tile.
object
The organization’s discovery lifecycle stage.
How current the discovered inventory is, across the organization’s accounts.
object
One tile on the overview. A tile is ready (it carries a value), pending (the capability behind it has not shipped, and pending_reason says which), or error (its provider failed or timed out — the rest of the response is still served).
object
Primary count. Ready tiles only.
Optional label/value pairs. Ready tiles only.
One label/value pair in a tile breakdown, such as a resource type and its count.
object
Optional list, such as recent changes. Ready tiles only.
One entry in a list tile.
object
Pending tiles only.
Human-readable failure. Error tiles only.
Example
{ "onboarding_state": "no_accounts", "tiles": [ { "key": "resources_total", "status": "ready", "breakdown": [ { "label": "aws_s3_bucket" } ], "pending_reason": "requires_ownership" } ]}No valid credential was presented, or it has expired.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "unauthorized", "message": "authentication required"}{ "code": "invalid_credentials", "message": "invalid email or password"}{ "code": "invalid_token", "message": "invalid or expired token"}{ "code": "token_reuse", "message": "session revoked"}{ "code": "webhook_unauthorized", "message": "webhook verification failed"}Authenticated, but not permitted to perform this action.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "forbidden", "message": "you do not have permission to perform this action"}{ "code": "csrf_failed", "message": "missing or invalid CSRF token"}{ "code": "account_deactivated", "message": "your account is deactivated; contact your administrator"}{ "code": "ai_disabled", "message": "the AI assistant is disabled for this organization"}An unexpected failure. Diagnostic detail is logged server-side and
deliberately not returned. Quote the X-Request-Id response header when
reporting one.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "internal_error", "message": "internal server error"}