API Builder
Import, govern, and publish REST APIs as versioned, auditable tools your agents can call.
API Builder wraps an imported OpenAPI spec for some upstream REST API in an ApiDefinition, and carries it through the same kind of draft → staged → published lifecycle Agent Builder already uses for workflows — with its own audit log, version snapshots, and rollback. Publishing an API automatically registers it as a Tool Server behind Hrida.ai's built-in API Gateway, so it's immediately callable by any Agent Builder agent with rate limits, caller identity, auditing and masking applied to every call. Agent Builder builds the agent workflows; API Builder builds and governs the REST APIs those workflows call.
What you can build
| Use case | How |
|---|---|
| Turn a partner's OpenAPI spec into a governed agent tool | Import spec → draft → stage → approve & publish |
| Expose a legacy SOAP/XML or form-encoded service as a clean JSON tool | Publish + an AI Protocol Mapper (JSON ⇄ XML/SOAP/form) |
| Normalize an upstream API's inconsistent JSON shape | An AI Message Mapper (JSON reshape via a sandboxed expression) |
| Roll back a breaking upstream contract change | Version snapshots + rollback |
| Give a partner team scoped, auditable publish rights | API Spaces with per-space roles |
| Call an OAuth2-protected or mutual-TLS enterprise API | Upstream Authentication & TLS |
| Keep PAN, Aadhaar or card numbers out of agent conversations | Response masking |
| Stop a runaway agent from flooding a partner API | Rate limits per API and per user |
| See who called an API and why calls failed | Gateway Call Log |
Key Features
| 📥 Spec import | Create a draft API definition from an OpenAPI 3.x or Swagger 2.0 spec in JSON or YAML — imported from a file or pasted. The name, description and base URL are filled in from the spec. |
| 📋 Governed lifecycle | Draft → Staged (In Review) → Published, with reject and revise-back-to-draft transitions |
| 🕵️ Audit log | Every create/update/publish/unpublish action is recorded against the API definition |
| 🔢 Version snapshots & rollback | An immutable snapshot is taken on every publish (and before every rollback); restore the spec and upstream URL from any prior snapshot |
| 🏢 API Spaces & roles | api_developer, lifecycle_manager, space_admin roles, scoped per API Space — separate from Agent Builder's own Catalogs & Spaces |
| 🔌 Auto tool-server registration | Publishing an API instantly registers it in the shared Tool Server list — callable by Agent Builder agents with no extra setup |
| 🧩 AI Message Mappers | Reshape upstream JSON requests/responses with an AI-assisted, sandboxed expression, plus a built-in test runner |
| 🔀 AI Protocol Mappers | Convert JSON ⇄ XML / SOAP / form-urlencoded, with deterministic auto-detection from a sample and an AI fallback for ambiguous cases |
| 🛡️ Built-in API gateway | Every published API is called through the gateway — the upstream credential is never exposed to agents or the Tool Server config |
| 🚦 Gateway policy | Rate limits, size caps, opt-in request validation, signed caller identity and response masking, per API |
| 🔑 Enterprise upstream auth | Bearer, API key, Basic and OAuth2 client credentials, plus custom CA and mutual TLS — secrets encrypted at rest and rotatable without re-approval |
| 🧾 Gateway call log | One audit row per call — user, operation, status, error code and duration, never payloads |
| 🌐 Network protections | Loopback and cloud-metadata upstreams blocked, DNS re-checked per call, and an admin-managed upstream host allow-list |
| 🧵 Optimistic locking | Concurrent edits are caught with an edit-sequence check rather than silently overwriting each other |
Builder layout
┌────────────────────────────────────────────────────────────┐
│ List view (/api-builder) │
│ Tabs: Published · In Review · Drafts — per-space filter │
│ Search, create, delete │
└────────────────────────────────────────────────────────────┘
│ open an API
▼
┌────────────────────────────────────────────────────────────┐
│ Header: name, status badge, version, lifecycle actions │
├──────────────────────────────────────────────────────────────┤
│ Identity — description, slug │
│ Upstream — base URL, auth type and settings, TLS │
│ Gateway policy — limits, validation, identity, masking │
│ Security — rotate gateway secret / upstream credential │
│ Gateway calls — recent calls and 24-hour summary │
│ OpenAPI spec — JSON or YAML, import or paste │
│ Message Mappers (JSON reshape, per operation) │
│ Transport Protocol Mappers (XML/SOAP/form, per operation) │
└────────────────────────────────────────────────────────────┘
- List view — tabs group API definitions by lifecycle stage (Published / In Review / Drafts), with a per-space filter and search. Admins also get Gateway settings here, for the upstream host allow-list.
- Header bar — shows the current status and version, and surfaces only the lifecycle actions the caller's role allows: Submit for Review, Reject / Approve & Publish, or Move to Draft / Pull Back to Draft.
- Identity, Upstream, Gateway policy, and the two mapper panels are edited inline; a definition can only be edited while in Draft or Rejected status — a staged or published one must be pulled back to draft first, mirroring Agent Builder's own edit rule. The Security card (secret rotation) works on published APIs, and Gateway calls shows activity for any saved API.
- Version history, rollback, and the full audit log are available today via the API rather than a dedicated screen in this first release of the builder UI.
Quick start
- Go to API Builder and click Create API, then Import file… (JSON or YAML) or paste the spec. The name, description and base URL are filled in from the spec.
- Check the upstream base URL and choose an auth type — none, bearer token, API key, Basic or OAuth2 client credentials — and add TLS certificates if the upstream needs them.
- (Optional) Adjust the gateway policy: rate limits, size caps, request validation, required caller identity and masking. The defaults suit most APIs.
- (Optional) Add Message Mappers and/or Protocol Mappers if the upstream's shape or transport doesn't match what you want agents to see.
- Click Submit for Review.
- A
lifecycle_manager,space_admin, oradminclicks Approve & Publish — the API is now published behind the API Gateway and automatically registered as a Tool Server for the API's owner and space members. - Attach the new tool server to any Agent Builder agent — see Agent Builder → Built-in Tools — and watch its traffic under Gateway calls.
Next steps
- Lifecycle, Versions & Audit Log — the draft/staged/published state machine, rollback, and audit trail
- API Catalogs, Spaces & Roles — the parallel space/role system that scopes who can do what
- Tool Server Publishing — what actually happens when an API is published
- AI Message Mappers — reshaping JSON requests and responses
- AI Protocol Mappers — converting to/from XML, SOAP, and form-urlencoded
- API Gateway — how every published API is called at runtime
- Gateway Policy & Security — rate limits, size caps, validation, caller identity, masking and the host allow-list
- Upstream Authentication & TLS — auth types, mutual TLS and secret rotation
- Gateway Call Log — per-call audit records
- Agent Builder → Built-in Tools — how a published API Builder API shows up as a callable tool