Agents & APIs

Developers

Machine-readable access to KONDEVS: the MCP server, markdown pages, feeds and the Content API, with errors, limits and versioning documented.

KONDEVS is an integration, BPM and AI consultancy. This site is built to be read and used by AI agents as well as people: everything below is live, and most of it needs no key.

Quickstart: no key needed

List the tools of the MCP server, then search the articles:

curl -s https://www.kondevs.com/mcp -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'

curl -s https://www.kondevs.com/mcp -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"search_articles","arguments":{"query":"webMethods","limit":3}}}'

Read any page as markdown, or list the HTTP endpoints:

curl -s https://www.kondevs.com/services/eai-integration/ -H "Accept: text/markdown"

curl -s https://www.kondevs.com/api/

Public interfaces

Public machine interfaces: address, access and what each gives you
InterfaceAddressAccessWhat it gives you
MCP serverPOST /mcp, card server-card.jsonnoneJSON-RPC 2.0 over Streamable HTTP. Tools: search_articles, get_article, list_services, get_company_info.
A2A agentPOST /api/a2a, card agent-card.jsonnonemessage/send: questions about KONDEVS and the Content Hub.
Markdownany pagenoneSend Accept: text/markdown: YAML frontmatter and the page content, no site chrome. An unknown address answers 404 in markdown too.
Feedsfeed.xml (RSS), feed.json (JSON Feed)noneThe newest 50 articles in full: key takeaways, body, FAQ, sources.
Site guidesllms.txt, llms-full.txt, sitemap.xmlnoneWhat the site holds, when to use it, every page.
API descriptionsopenapi.json, api-catalog, /api/noneOpenAPI 3.1, the RFC 9727 catalog and a JSON index of every endpoint.
Discoveryai-catalog.json, agent skillsnoneThe ARD catalog and the agent skills index.
HealthGET /api/healthnoneLiveness probe.

Content API for publishing partners

The Content API publishes, updates and removes Content Hub articles. It serves content partners such as the VISIBILIO platform; it is not an open, self-service API.

  • API keys. There is no self-service sign-up. KONDEVS issues keys to vetted partners: write to info@kondevs.com with your organisation, the integration purpose, the expected volume and the scope you need (content:read or content:write). GET /api/oauth/register returns the same instructions as JSON.
  • Authentication. Authorization: Bearer <key>, or exchange the key for a one-hour token with OAuth 2.0 client_credentials at POST /api/oauth/token (ES256, keys at jwks.json). The full guide is auth.md.
  • Endpoints. GET /api/content/catalog, POST /api/content/, PUT /api/content/{slug}, DELETE /api/content/{slug}, and the public GET /api/content/version. Schemas and examples are in openapi.json.
  • Testing without side effects. There is no separate sandbox environment. POST /api/content/?dry_run=true runs authentication, limits and the full validation and stores nothing, so it is the safe way to test a payload.
  • Safe retries. Send an Idempotency-Key header with POST /api/content/: a retry with the same key and body gets the first answer again (marked Idempotent-Replayed: true) for 24 hours; the same key with a different body answers 422. PUT and DELETE are idempotent by definition.
curl -s -X POST "https://www.kondevs.com/api/content/?dry_run=true" \
  -H "Authorization: Bearer $KONDEVS_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: 6f1c0b8e-2d4a-4f7e-9a51-3c2e8d7b1a90" \
  -d @article.json

Errors

Every /api/* error is JSON with a stable code, a message, a hint and this page as docs. Validation failures add the field list in errors.

HTTP/1.1 404 Not Found
Content-Type: application/json; charset=utf-8

{
  "status": "error",
  "code": "not_found",
  "message": "No API endpoint at /api/nope.",
  "hint": "Check the path. GET /api/ lists the endpoints; /openapi.json describes them.",
  "docs": "https://www.kondevs.com/developers/"
}

Codes: bad_request, validation_failed, unauthorized, forbidden, not_found, method_not_allowed, conflict, payload_too_large, unsupported_version, invalid_idempotency_key, idempotency_key_reused, idempotency_in_progress, rate_limited, internal_error. Two protocols keep their own format: the OAuth endpoints answer as RFC 6749 defines (error, error_description), and /mcp and /api/a2a answer JSON-RPC 2.0 errors.

Rate limits

Rate limits per interface
InterfaceAddressLimitCounted
MCP server/mcp120 per minuteper IP
A2A agent/api/a2a60 per minuteper IP
Catalog/api/content/catalog60 per minuteper IP
Publish, update, delete/api/content/**30 per hour eachper IP
OAuth token, registration/api/oauth/*30 per minuteper IP

Rate-limited responses carry RateLimit-Policy and RateLimit (the IETF RateLimit header fields: quota, window, remaining, seconds to reset) and X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset (Unix time). A 429 adds Retry-After in seconds.

Versioning

The Content API is at version 1.1.0: every response carries x-content-api-version, and GET /api/content/version returns it with the rendering capabilities of this site. Changes within major version 1 only add fields. A client can pin the major version with X-Content-API-Version: 1; a request for another major version is refused with 400 unsupported_version. Anything that is going to be removed will be announced on this page and with Deprecation and Sunset response headers before it goes.

Questions

Write to info@kondevs.com. For what KONDEVS does and when to call on it, read llms.txt.

Have a project in mind?

Tell us the objective, and we'll tell you honestly how we would approach it.

Discuss your project