Skip to main content

API Builder

Import, govern, and publish REST APIs as versioned, auditable tools your agents can call.

API Builder wraps an imported OpenAPI spec for some upstream REST API in an ApiDefinition, and carries it through the same kind of draft → staged → published lifecycle Agent Builder already uses for workflows — with its own audit log, version snapshots, and rollback. Publishing an API automatically registers it as a Tool Server behind Hrida.ai's built-in API Gateway, so it's immediately callable by any Agent Builder agent with rate limits, caller identity, auditing and masking applied to every call. Agent Builder builds the agent workflows; API Builder builds and governs the REST APIs those workflows call.


What you can build​

Use caseHow
Turn a partner's OpenAPI spec into a governed agent toolImport spec → draft → stage → approve & publish
Expose a legacy SOAP/XML or form-encoded service as a clean JSON toolPublish + an AI Protocol Mapper (JSON ⇄ XML/SOAP/form)
Normalize an upstream API's inconsistent JSON shapeAn AI Message Mapper (JSON reshape via a sandboxed expression)
Roll back a breaking upstream contract changeVersion snapshots + rollback
Give a partner team scoped, auditable publish rightsAPI Spaces with per-space roles
Call an OAuth2-protected or mutual-TLS enterprise APIUpstream Authentication & TLS
Keep PAN, Aadhaar or card numbers out of agent conversationsResponse masking
Stop a runaway agent from flooding a partner APIRate limits per API and per user
See who called an API and why calls failedGateway Call Log

Key Features​

📥 Spec importCreate a draft API definition from an OpenAPI 3.x or Swagger 2.0 spec in JSON or YAML — imported from a file or pasted. The name, description and base URL are filled in from the spec.
📋 Governed lifecycleDraft → Staged (In Review) → Published, with reject and revise-back-to-draft transitions
🕵️ Audit logEvery create/update/publish/unpublish action is recorded against the API definition
🔢 Version snapshots & rollbackAn immutable snapshot is taken on every publish (and before every rollback); restore the spec and upstream URL from any prior snapshot
🏢 API Spaces & rolesapi_developer, lifecycle_manager, space_admin roles, scoped per API Space — separate from Agent Builder's own Catalogs & Spaces
🔌 Auto tool-server registrationPublishing an API instantly registers it in the shared Tool Server list — callable by Agent Builder agents with no extra setup
🧩 AI Message MappersReshape upstream JSON requests/responses with an AI-assisted, sandboxed expression, plus a built-in test runner
🔀 AI Protocol MappersConvert JSON ⇄ XML / SOAP / form-urlencoded, with deterministic auto-detection from a sample and an AI fallback for ambiguous cases
🛡️ Built-in API gatewayEvery published API is called through the gateway — the upstream credential is never exposed to agents or the Tool Server config
🚦 Gateway policyRate limits, size caps, opt-in request validation, signed caller identity and response masking, per API
🔑 Enterprise upstream authBearer, API key, Basic and OAuth2 client credentials, plus custom CA and mutual TLS — secrets encrypted at rest and rotatable without re-approval
🧾 Gateway call logOne audit row per call — user, operation, status, error code and duration, never payloads
🌐 Network protectionsLoopback and cloud-metadata upstreams blocked, DNS re-checked per call, and an admin-managed upstream host allow-list
🧵 Optimistic lockingConcurrent edits are caught with an edit-sequence check rather than silently overwriting each other

Builder layout​

┌────────────────────────────────────────────────────────────┐
│ List view (/api-builder) │
│ Tabs: Published · In Review · Drafts — per-space filter │
│ Search, create, delete │
└────────────────────────────────────────────────────────────┘
│ open an API
▼
┌────────────────────────────────────────────────────────────┐
│ Header: name, status badge, version, lifecycle actions │
├──────────────────────────────────────────────────────────────┤
│ Identity — description, slug │
│ Upstream — base URL, auth type and settings, TLS │
│ Gateway policy — limits, validation, identity, masking │
│ Security — rotate gateway secret / upstream credential │
│ Gateway calls — recent calls and 24-hour summary │
│ OpenAPI spec — JSON or YAML, import or paste │
│ Message Mappers (JSON reshape, per operation) │
│ Transport Protocol Mappers (XML/SOAP/form, per operation) │
└────────────────────────────────────────────────────────────┘
  • List view — tabs group API definitions by lifecycle stage (Published / In Review / Drafts), with a per-space filter and search. Admins also get Gateway settings here, for the upstream host allow-list.
  • Header bar — shows the current status and version, and surfaces only the lifecycle actions the caller's role allows: Submit for Review, Reject / Approve & Publish, or Move to Draft / Pull Back to Draft.
  • Identity, Upstream, Gateway policy, and the two mapper panels are edited inline; a definition can only be edited while in Draft or Rejected status — a staged or published one must be pulled back to draft first, mirroring Agent Builder's own edit rule. The Security card (secret rotation) works on published APIs, and Gateway calls shows activity for any saved API.
  • Version history, rollback, and the full audit log are available today via the API rather than a dedicated screen in this first release of the builder UI.

Quick start​

  1. Go to API Builder and click Create API, then Import file… (JSON or YAML) or paste the spec. The name, description and base URL are filled in from the spec.
  2. Check the upstream base URL and choose an auth type — none, bearer token, API key, Basic or OAuth2 client credentials — and add TLS certificates if the upstream needs them.
  3. (Optional) Adjust the gateway policy: rate limits, size caps, request validation, required caller identity and masking. The defaults suit most APIs.
  4. (Optional) Add Message Mappers and/or Protocol Mappers if the upstream's shape or transport doesn't match what you want agents to see.
  5. Click Submit for Review.
  6. A lifecycle_manager, space_admin, or admin clicks Approve & Publish — the API is now published behind the API Gateway and automatically registered as a Tool Server for the API's owner and space members.
  7. Attach the new tool server to any Agent Builder agent — see Agent Builder → Built-in Tools — and watch its traffic under Gateway calls.

Next steps​

Hrida.ai is proprietary software of Zlabs Innovation. See the license for terms. © 2026 Zlabs Innovation.