canonical: https://jentic.com/apis/twin.so/twin-so

# Twin So Twin API

REST API for managing Twin AI web agents, runs, schedules, instructions, and webhooks. The API exposes 33 endpoints secured with apiKey authentication.

## For AI agents

Programmatically create API key, list API keys. Covers 33 operations with apiKey authentication.

## Scope

Does not handle payments, communications, or crm - use for developer tools only.

## Capabilities

- Create API key
- List API keys
- Revoke API key
- Get authenticated user
- Monitor Twin API operational status and events

## Use cases

### Developer Tools Operations

Use the Twin API to perform developer tools operations programmatically. The API provides 33 endpoints covering core functionality including create API key, list API keys, revoke API key.

Example prompt: Call POST `/api/public/v1/access-api-keys` to create API key

### Automated API Keys Management

Automate API keys operations by combining multiple Twin API endpoints. Agents can list API keys and then revoke API key in a single workflow.

Example prompt: Call GET `/api/public/v1/access-api-keys` to list API keys, then verify the result

### AI Agent Integration via Jentic

AI agents discover and call Twin API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle apiKey tokens manually.

Example prompt: Search Jentic for 'create API key', load the operation schema, and execute with Jentic-managed credentials

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| POST | `/api/public/v1/access-api-keys` | Create API key |
| GET | `/api/public/v1/access-api-keys` | List API keys |
| DELETE | `/api/public/v1/access-api-keys/{key_id}` | Revoke API key |
| GET | `/v1/me` | Get authenticated user |
| POST | `/v1/agents` | Create agent |
| GET | `/v1/agents` | List agents |
| GET | `/v1/agents/{agent_id}` | Get agent |
| DELETE | `/v1/agents/{agent_id}` | Delete agent |

## Key resources

- **API Keys** — Operations related to API Keys
- **Agents** — Operations related to Agents
- **Identity** — Operations related to Identity
- **Instructions** — Operations related to Instructions
- **Runs** — Operations related to Runs

## AI readiness

This API is usable in Jentic One now. Its AI-readiness score against Jentic's framework shows where it stands today and where improvements would make it even easier for agents to use.

- **Score:** 67 / 100
- **Maturity:** AI-Aware
- **Dimensions:**
  - Foundational Compliance: 93 / 100
  - Developer Experience & Jentic Compatibility: 63 / 100
  - AI-Readiness & Agent Experience: 50 / 100
  - Agent Usability: 94 / 100
  - Security: 50 / 100
  - AI Discoverability: 100 / 100
- **View full report:** https://jentic.com/apis/twin.so/twin-so/scorecard
- **How the score is calculated:** https://docs.jentic.com/reference/api-readiness-framework/overview/
- **More about the dimensions:** https://docs.jentic.com/reference/api-readiness-framework/specification/#dimensional-model-overview

### Score it yourself

Every API in the directory is allowlisted, so you can re-score it with no key required.

- **Score your own API:** https://jentic.com/scorecard.md
- **Scoring CLI agent skill:** https://github.com/jentic/jentic-api-scorecard/blob/main/skills/jentic-api-scorecard/SKILL.md

```sh
npx @jentic/api-scorecard-cli score <openapi-url>
```

## Why Jentic

- **Setup:** Wiring the Twin API by hand means managing an x-api-key header against the builder.twin.so host, minting and rotating access API keys, and handling retries yourself. Through Jentic you install once, import the Twin API from the API Directory, store the API key once, and your agent calls it.
- **Permission scoping:** The Twin API puts the agent and key ids in the URL path (`/v1/agents/{agent_id}`, `/api/public/v1/access-api-keys/{key_id}`), so a rule can pin your agent to one Twin agent. You choose the operations it may call, so destructive ones like deleting an agent or revoking an access API key are not included unless you add them.
- **Credential handling:** Your Twin API key is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'create an agent' or 'list access API keys', and Jentic returns the matching Twin API operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

## Related APIs

- **Github** — Alternative developer tools API
- **Gitlab** — Alternative developer tools API

## FAQ

### What authentication does the Twin API use?

The Twin API uses an API key passed in the `x-api-key` header. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.

### Can I create API key with the Twin API?

Yes. Use the POST `/api/public/v1/access-api-keys` endpoint. The API returns structured JSON responses that agents can parse and act on directly.

### What are the rate limits for the Twin API?

Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.

### How do I create API key through Jentic?

Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'create API key'. Jentic returns the matching Twin API operation with its input schema. Load the schema and execute the call - credentials are injected automatically.

### How many endpoints does the Twin API have?

The Twin API exposes 33 endpoints covering API keys, agents, identity operations.

### Can I limit what my agent is allowed to do with the Twin API?

Yes. Jentic One is self-hosted by you, so your own rules decide which Twin API operations and credentials the agent may use. You pick the operations it can call, so destructive ones like DELETE `/v1/agents/{agent_id}` or revoking an access key at DELETE `/api/public/v1/access-api-keys/{key_id}` are excluded unless you add them. Because Twin puts the agent and key ids in the URL path, a rule can pin the agent to a single Twin agent rather than your whole account.
