# Cisco Crosswork > Cisco's service-provider network automation portfolio: Crosswork Network Controller (CNC), Crosswork Data Gateway (CDG), Zero Touch Provisioning (ZTP), Optimization Engine (COE), the NCAHI platform services and Crosswork Workflow Manager (CWM). Crosswork is CUSTOMER-DEPLOYED software. There is no Cisco-hosted Crosswork API endpoint, no sign-up and no API key: every base URL below is relative to a host the customer installs and operates. Generated by API Evangelist on 2026-08-19 from this repository. method: generated. Cisco publishes no llms.txt of its own (https://developer.cisco.com/llms.txt returns 404). ## How to call it - Base URLs are paths, not hosts. Cisco writes them as `https://$CNC_HOST:$CNC_PORT/crosswork/...` - Authentication is a two-step ticket exchange against the customer's own instance: 1. `POST https://{cnc-host}:{cnc-port}/crosswork/sso/v1/tickets` (form-encoded username + password) to get a Ticket Granting Ticket 2. `POST https://{cnc-host}:{cnc-port}/crosswork/sso/v2/tickets/jwt` to exchange the TGT for a JWT 3. Send `Authorization: Bearer {jwt}` on every request - Authorisation is RBAC configured inside the instance. There are no OAuth scopes. - RESTCONF families use `Content-Type: application/yang-data+json` and `Accept: application/yang-data+json`. The rest use `application/json`. - There are no rate limits, no 429, no Retry-After, no idempotency keys and no request-id header. See rate-limits/ and conventions/. ## Base paths - `/crosswork/proxy/nso/restconf` — service provisioning via NSO - `/crosswork/nbi/cat-inventory/v1/restconf` — CAT service inventory - `/crosswork/nbi/optima/v2/restconf` — COE transport engineering - `/crosswork/nbi/topology/v3/restconf` — topology - `/crosswork/inventory/` — devices, credentials, providers, tags, destinations, data-gateway enrolments - `/crosswork/platform` — health, alerts - `/crosswork/dg-manager` — Crosswork Data Gateway - `/crosswork/ztp/` — Zero Touch Provisioning - `/crosswork/imagesvc/` — image service - `/crosswork/authconfig`, `/crosswork/aaa`, `/crosswork/password` — auth, RBAC, credentials - `/crosswork/cwm/v2` — Crosswork Workflow Manager 2.1 ## Agent surface - MCP: `POST https://{cwm-host}:{cwm-port}/crosswork/cwm/v2/mcp` — Crosswork Workflow Manager 2.1 speaks MCP over JSON-RPC 2.0 (initialize, tools/list, tools/call, ping, notifications/initialized, logging/setLevel). Requires a Crosswork-minted JWT. The tool list cannot be enumerated anonymously; see mcp/cisco-crosswork-mcp.yml. - A2A: no agent card. `/.well-known/agent-card.json` and `/.well-known/agent.json` return 404 on every Cisco host probed. ## Specifications in this repository - openapi/ — 99 refined OpenAPI 3.2.0 documents, one per resource - openapi/_original/ — 67 harvested source documents (Swagger 2.0), unmodified except for a provenance stamp - grpc/ — 18 first-party proto3 definitions for the Crosswork Data Platform Model telemetry records - overlays/ — the OpenAPI Overlay recording API Evangelist's enhancements to the Workflow Manager contract ## Artifacts in this repository - authentication/ — the JWT ticket-exchange profile and every declared security scheme - conventions/ — base paths, media types, pagination (three incompatible styles), versioning, error envelopes - errors/ — 1,895 declared error responses, five envelope shapes, no RFC 9457 - conformance/ — what Crosswork does and does not implement (RESTCONF and YANG yes; OAuth 2.0, OIDC, RFC 9457, idempotency no) - data-model/ — the inventory graph and the workflow graph, and why they do not touch - asyncapi/ — the event and telemetry surface: CWM event types, CDG destinations, the notification stream - lifecycle/ — release trains, the absence of a deprecation policy, and the spec-repository decay signal - changelog/ — the release-notes set, which is prose rather than an API changelog - packages/ — the CiscoDevNet SDK distributions and what they are pinned to - plans/ — no published pricing; Essentials and Advantage are quoted by sales - rate-limits/ — an honest zero - sandbox/ — the DevNet Crosswork Automation Sandbox (a reservable lab, not a sandbox API) - security/ — domain security probes, the PSIRT disclosure programme, CSAF, the Cisco Trust Portal - well-known/ — every /.well-known/ path probed and what it returned - skills/ — packaged agent skills grounded in real operationIds ## Cisco's own sources - Crosswork developer documentation: https://developer.cisco.com/docs/crosswork/ - Crosswork Network Controller 7.2 APIs: https://developer.cisco.com/docs/crosswork/network-controller/ - Crosswork Workflow Manager API: https://developer.cisco.com/docs/crosswork/workflow-manager/ - Crosswork Planning API: https://developer.cisco.com/docs/crosswork/planning/ - Published OpenAPI/Swagger repository: https://github.com/CiscoDevNet/crosswork-openapi-spec (last commit 2022-12-14) - SDK and downloadable tools: https://github.com/CiscoDevNet/Crosswork-SDK - Postman collections: https://github.com/CiscoDevNet/postman-for-Cisco-Crosswork (last commit 2019-06-04) - Security policy: https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html - Trust Portal: https://trustportal.cisco.com/ ## What is NOT here - No hosted API, no free tier, no published price - No AsyncAPI, no GraphQL, no agent card - No published rate limits, deprecation policy, SLA or status page covering the on-premises products - No error-code reference and no OAuth scopes