Platform operations
Account and administrator API parity, credentials, and workflow control.
Every authenticated website operation accepts an API key with the appropriate scope. Use x-api-key or Authorization: Bearer. Repository ownership, organization membership and administrator roles are checked on each request.
| Website capability | API |
|---|---|
| Profile, preferences, avatar | /api/account/profile, /api/account/preferences, /api/account/avatar |
| Keys | GET, POST, DELETE /api/account/keys (account) |
| Usage and credits | GET /api/account/usage |
| Authentication status and security log | GET /api/account/security, GET /api/account/security-log (account) |
| Password setup, account deletion | POST /api/account/password, POST /api/account/delete (account) |
| Organizations, invitations, devices, email, two-factor authentication | /api/auth/** (account); generated schema below |
| Notifications | GET, PATCH /api/notifications |
| Repository settings and author claims | /api/repositories/{repositoryId}, /visibility, /author-claims |
| Submit paper and observe processing | POST /api/repositories, GET /api/processing?repositoryId=... |
| Administrator dashboard | GET /api/admin/overview |
| Users and roles | /api/admin/users, /api/admin/users/{userId}/role |
| Repository administration | /api/admin/repositories; /{repositoryId}/details, /visibility, /transfer, /delete |
| Author claim administration | GET /api/admin/author-claims; POST /api/admin/author-claims/{claimId}/revoke |
| Workflow administration | /api/admin/jobs, /api/admin/jobs/{jobId}, /retry, /cancel |
| Diagnostic and artifact downloads | /api/admin/jobs/{jobId}/diagnostics/{diagnosticId}/download, /artifacts/{artifactId}/download |
| Agent configuration and presets | /api/admin/agent-config, /api/admin/agent-presets |
| Articles and author outreach | /api/admin/articles, /api/admin/outreach |
All /api/admin/** endpoints require both an admin scope and a current administrator account. A normal key belonging to an administrator is insufficient. Choose Administrator key on the key page to issue one.
Machine-readable discovery
/api/openapi.json: business endpoint inventory plus detailed research API schemas./api/auth/open-api/generate-schema: schemas generated from the installed authentication, organization and security endpoints.- Existing endpoint reference pages document payloads for submission, processing and research operations. Inventory entries without a request schema are discovery records, not a complete SDK generation contract.
Create a scoped key
curl -X POST https://citeark.co/api/account/keys \
-H "x-api-key: $CITEARK_API_KEY" -H 'Content-Type: application/json' \
--data '{"name":"research-reader","expiresIn":86400,"permissions":["read"]}'The caller needs account. Child scopes and expiration cannot exceed the calling key's authority. The full secret is returned only at creation. DELETE /api/account/keys accepts {"keyId":"..."}.
Continue a failed workflow
curl -X POST "https://citeark.co/api/admin/jobs/$JOB_ID/retry" \
-H "x-api-key: $CITEARK_ADMIN_API_KEY" \
-H 'Content-Type: application/json' -H 'Idempotency-Key: repair-attempt-1' \
--data '{"mode":"continue"}'continue creates a linked continuation; resume reuses a valid published plan; retry requeues the existing task. The idempotency key deduplicates continuation creation (continue and resume). Keep the same key when retrying an uncertain response. Prior artifacts and the task lineage remain traceable. Query the returned job ID to observe progress; request acceptance does not mean scientific completion.
Password challenges, email confirmation, provider consent, two-factor codes and payment confirmation still apply. Internal worker and payment-webhook endpoints use their service credentials or signatures; they are not website-user operations.
Public content is available through GET /api/news, GET /api/news/{slug}, GET /api/daily, GET /api/daily/{date}, GET /api/profiles/{slug}, and GET /api/venues?series=iclr&edition=2026.
For a failed compiler job with its own durable checkpoint, administrators can send
{"mode":"retry","compilerRepair":true} to /api/admin/jobs/{jobId}/retry.
This explicitly selects a cumulative 60-minute compiler repair limit, including time
already consumed. The checkpoint identity is audited; a mismatch stops recovery.
The paper budget and scientific experiment limits remain unchanged.
Codex subscription accounts
Administrator Agent presets accept optional codexAccountId (Codex only; lowercase letters, digits and hyphens, up to 48 characters). Set it to a provisioned dedicated account ID to use ChatGPT sign-in for the execution agent; set null to restore API mode. The same field is available in the administrator UI and POST/PATCH preset APIs with an admin-scoped API key. Login tokens are never returned. The API provider configuration remains necessary for independently billed assessment.