Install Jentic One Beta
Jentic One is a self-hosted execution layer for AI agents. It lets your agent call the Reflag Management API, or any other public or private API you need. You set the rules, the agent never sees your credentials, and every call is logged.
Two steps, two machines. Install the instance in a safe environment, then register your agent from wherever it runs.
Step 1: Jentic One Host machine
# On the machine that will host your Jentic One instance:
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Freflag.com%2Freflag" | shStep 2: Agent machine
# On the machine where your agent runs (keep this separate from the instance):
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Freflag.com%2Freflag" | sh
jentic register # connects your agent to your Jentic One instanceJentic One is in public beta. The setup above keeps your agent separate from the instance, which is what you want before using real credentials: an agent running as the same OS user as Jentic One can read its stored keys directly. Just evaluating? A single local install is fine to start. See the secure deployment guide for the tiers.
What an agent can do with Reflag Management API.
Get details of an application
List of applications
Create a flag
Update a flag
Monitor Reflag Management API operational status and events
GET STARTED
Patterns agents use Reflag Management API for, with concrete tasks.
★ Developer Tools Operations
Use the Reflag Management API to perform developer tools operations programmatically. The API provides 12 endpoints covering core functionality including get details of an application, list of applications, list environments for application.
Call GET /apps/{appId} to get details of an application
Automated Apps Management
Automate apps operations by combining multiple Reflag Management API endpoints. Agents can list of applications and then list environments for application in a single workflow.
Call GET /apps to list of applications, then verify the result
AI Agent Integration via Jentic
AI agents discover and call Reflag Management API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle bearer tokens manually.
Search Jentic for 'get details of an application', load the operation schema, and execute with Jentic-managed credentials
12 endpoints — feature flag management api.
METHOD
PATH
DESCRIPTION
/apps/{appId}
Get details of an application
/apps
List of applications
/apps/{appId}/environments
List environments for application
/apps/{appId}/environments/{envId}
Get environment details
/apps/{appId}/flags
Create a flag
/apps/{appId}/flags
List flags for application
/apps/{appId}/flags/{flagId}
Update a flag
/apps/{appId}/flags/{flagKey}/targeting/{envId}
Get flag targeting for an environment
/apps/{appId}
Get details of an application
/apps
List of applications
/apps/{appId}/environments
List environments for application
/apps/{appId}/environments/{envId}
Get environment details
/apps/{appId}/flags
Create a flag
/apps/{appId}/flags
List flags for application
/apps/{appId}/flags/{flagId}
Update a flag
/apps/{appId}/flags/{flagKey}/targeting/{envId}
Get flag targeting for an environment
What agents get from Jentic-routed access to this vendor.
Setup
Wiring the Reflag Management API by hand means setting its bearer token on every request and building your own retry handling against the app.reflag.com host. Through Jentic you install once, import the Reflag Management API from the API Directory, store the token once, and your agent calls it.
Permission scoping
The Reflag Management API puts the app, environment, and flag ids in the URL path (/apps/{appId}/flags/{flagId}), so a rule can pin your agent to one app and let it read and manage only that app's flags and environments. You choose the operations it may call, so state-changing ones like creating or patching a flag are not included unless you add them.
Credential isolation
Your Reflag Management API bearer token is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
Intent-based discovery
Agents search Jentic by intent such as 'get details of an application' or 'list feature flags', and Jentic returns the matching Reflag Management API operation with its input schema so the agent calls the right endpoint without browsing the reference docs.
Alternatives and complements available in the Jentic catalogue.
Specific to using Reflag Management API through Jentic.
What authentication does the Reflag Management API use?
The Reflag Management API uses a Bearer token in the Authorization header. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.
Can I get details of an application with the Reflag Management API?
Yes. Use the GET /apps/{appId} endpoint. The API returns structured JSON responses that agents can parse and act on directly.
What are the rate limits for the Reflag Management API?
Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.
How do I get details of an application through Jentic?
Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'get details of an application'. Jentic returns the matching Reflag Management API operation with its input schema. Load the schema and execute the call - credentials are injected automatically.
How many endpoints does the Reflag Management API have?
The Reflag Management API exposes 12 endpoints covering apps operations.
Can I limit what my agent is allowed to do with the Reflag Management API?
Yes. Because the Reflag Management API puts the app, environment, and flag ids in the URL path such as /apps/{appId}/flags/{flagId}, a rule in your self-hosted Jentic One instance can pin the agent to a single app and let it read and manage only that app's flags and environments. You decide which operations the agent may call, so read-only calls like GET /apps/{appId} and GET /apps/{appId}/flags can be allowed while state-changing operations such as POST /apps/{appId}/flags or PATCH /apps/{appId}/flags/{flagId} stay out of reach unless you add them. Your own rules and stored credentials, not the agent, govern what it can do.
For Agents
Programmatically get details of an application, list of applications. Covers 12 operations with bearer authentication.
Use for: I need to details of an application, I want to of applications, Search for environments for application, Find all environment details
Not supported: Does not handle payments, communications, or crm - use for developer tools only.
Feature flag Management API. The API exposes 12 endpoints secured with bearer authentication.
This API is usable in Jentic One now. Its AI-readiness score against Jentic's framework shows where it stands today and where improvements would make it even easier for agents to use.
Base layer of spec validity and structural soundness.
Aggregated quality score from linter diagnostics, weighted by severity.
Percentage of `$ref` references that resolve successfully.
Checks whether the API description parses successfully and conforms to its declared specification (e.g., OpenAPI).
Structural correctness score based on schema issues using logarithmic dampening.
Clarity, completeness, and ingestion readiness for developers and tooling.
How richly the API is illustrated with examples.
Percentage of examples that conform to their schemas.
Percentage of operations with complete response definitions (success, client error, server error).
Health of API ingestion, bundling, and resolution within Jentic pipelines.
Semantic breadth, depth, and agent comprehension for AI systems.
Coverage of descriptions across API elements.
Coverage of RFC 9457 Problem Details for error responses.
Coverage, uniqueness, and casing consistency of operationIds for AI inference.
Coverage of summaries across operations/tags/info.
Functional utility, complexity comfort, and AI orchestration readiness.
Agent comfort level based on API operational and structural complexity.
Trust, risk posture, and security compliance.
Average quality of security schemes based on authentication method strength (weakest link for OAuth2).
Findability, semantic richness, and reasoning readiness.
Clarity and depth of descriptions across API elements.
Score it yourself
Every API in the directory is allowlisted, so you can re-score it with no key required.
npx @jentic/api-scorecard-cli score <openapi-url>