afka uses analytics cookies to see how visitors use the site, and a service that can identify the company a visitor works for. We do not sell your data. Decline and none of it loads.
File a task from your own code and governed afka agents run it end to end: research, outreach, support replies, hiring pipelines, content. You read status and artifacts as they land, and a webhook tells you the moment the work is done or a decision is needed.
# file a task
POST https://api.afka.ai/v1/tasks
{ "prompt": "Find 20 lookalike leads and draft the first touch" }
# 202 { "task_id": "task_5f2c", "status": "queued" }The API speaks to the same runtime as the app, which is also why it obeys the same rules as the app.
One call files a task in plain language. The assistant routes it to the right agent, or you target a specific agent yourself, and you read the run as it happens.
task.finished when the work completes, approval.requested the moment an agent needs a human decision, and budget.reached when a key meets its monthly cap.
Every key takes a monthly spend cap in US dollars. At the cap, calls stop cleanly. Nothing overspends in silence.
The API is small on purpose: tasks in, status and artifacts out, webhooks when something finishes or needs you.
# file a task
POST https://api.afka.ai/v1/tasks
{ "prompt": "Find 20 lookalike leads and draft the first touch" }
# 202 { "task_id": "task_5f2c", "status": "queued" }
# read the run
GET https://api.afka.ai/v1/tasks/task_5f2c
{ "status": "done", "credits_spent": 412, "artifacts": [ "art_9d1e" ] }
# and afka calls you back
{ "event": "task.finished", "task_id": "task_5f2c", "workspace": "ws_main" }If a person can do it in the workspace, a key with the right scopes can do it from code.
One call files a task in plain language. The assistant routes it to the right agent, or you target a specific agent yourself.
Status, the step by step run trace, cost, and the artifacts an agent produced, readable the moment they exist.
List what is waiting on a human, then approve or reject from your own tools. Sensitive actions never run without a decision.
Push policies, prices and documents from your systems, so every agent answers from the same source of truth.
Deploy, pause and budget agents from code. They are the same governed identities you see in the workspace.
Subscribe once and afka calls you back: task finished, approval requested, budget reached. Signed, retried, replayable.
The same control plane that governs people and agents governs every key you mint.
Each key carries exactly the capabilities you grant, from read only to full delegation, and never more than the person who created it holds.
Every key takes a monthly spend cap in US dollars. At the cap, calls stop cleanly. Nothing overspends in silence.
API traffic passes the same approval gates. An agent asked to do something sensitive still waits for a human, whoever asked.
Every call, and every key created, rotated or revoked, lands in the append-only audit log with the identity that did it.
Subscribe once, and every finished task, every decision waiting on a human, and every budget ceiling reaches your own systems within seconds.
# every delivery, signed
POST https://your-app.example/afka/hooks
x-afka-event: task.finished
x-afka-delivery: d_8f3a1c9e # stable across retries, dedupe on it
x-afka-signature: sha256=<hex digest>
{ "event": "task.finished", "task_id": "task_5f2c", "created_at": "2026-08-10T06:12:04Z" }
# verify the RAW bytes, before you parse
expected = hmac_sha256(signing_secret, raw_body).hexdigest()task.finished when the work completes, approval.requested the moment an agent needs a human decision, and budget.reached when a key meets its monthly cap. One delivery per event, so a client looping against a capped key gets a single notice rather than a storm.
Every delivery carries an HMAC SHA256 signature over the raw body. Verify before you parse: re-serialising the JSON changes the bytes, and the digest with them. The timestamp lives inside the signed body rather than in a header, so a captured delivery cannot be replayed later, and anything older than five minutes is refused.
If your endpoint is down, afka retries six times with a widening gap and keeps the delivery id stable so you can safely ignore a repeat. Nothing in your workspace waits on your server: the approval is still created, the task still finishes, and every attempt lands in your audit log, including the moment afka stops trying.
Endpoints are registered in your dashboard over HTTPS. The signing secret is shown once, at registration, and never again.
Named keys with expiry and one click revocation, IP allowlists, per key rate limits, and the same SSO, DPA and SLA path as the rest of afka on Enterprise.
Talk to salesKeys live in your dashboard under Settings, API. Scoped, budgeted, revocable in one click.
Create a workspace, mint a key in Settings, and your first task is one request away.