# Corva AI > Corva is a Houston-based real-time data and analytics platform for upstream oil and gas — > drilling, completions, geoscience and sustainability. It ingests rig sensor and operational data > and exposes it through two REST APIs plus Dev Center, an app-hosting environment where customers > build and run their own applications on Corva data. This file is GENERATED by API Evangelist from Corva's published contracts and documentation. Corva does not publish an llms.txt of its own (probed 2026-09-05: /llms.txt returns 404 on www.corva.ai, dc-docs.corva.ai and api.corva.ai). ## Two APIs, two hosts Corva's single most important integration fact: there are TWO APIs on TWO different hosts, and most integrations need both. - **Platform API** — https://api.corva.ai — what a thing IS. Wells, rigs, pads, programs, frac fleets, drillout units, users, dashboards, alerts, apps, tasks. 513 paths, 771 operations. Contract: Swagger 2.0 at https://api.corva.ai/documentation/swagger.json (version v2.222.1). - **Data API** — https://data.corva.ai — what HAPPENED to it. Time, depth, reference and timeseries dataset records, aggregations, and writes to permitted customer datasets. 27 paths, 40 operations. Contract: OpenAPI 3.1.0 at https://data.corva.ai/api/v1/openapi.json. The documented flow is: query the Platform API for a well, read `attributes.asset_id` from the /v2/wells response (or the top-level `id` from /v2/assets), then filter a Data API dataset query by that asset_id. ## Authentication Two methods, neither of them OAuth. - API key: `Authorization: API YOUR_API_KEY` — the "API " prefix and the space are REQUIRED. Best for long-running services and scheduled exports. Note: key creation is NOT enabled by default for most customer users; it must be requested from a Corva representative. - Bearer JWT: `Authorization: Bearer YOUR_JWT`, obtained by POSTing `{"auth":{"email":..., "password":...}}` to https://api.corva.ai/v1/user_token. Access tokens default to a 7-day lifetime (read the `exp` claim rather than assuming); refresh tokens last 6 months and are exchanged at the same endpoint, which returns a NEW jwt AND a NEW refresh_token. Permission levels are read, read/write and admin, additionally scoped by company and owner. A valid key can still receive 403 when it lacks access to the requested resource. ## Reading data `GET /api/v1/data/{provider}/{dataset}/` with query-string parameters: - `query` — JSON object of match conditions, MongoDB-style operators, e.g. `{"asset_id": 12345, "timestamp": {"$gt": 1710000000}}` - `sort` — JSON object, 1 ascending / -1 descending - `limit` — REQUIRED, 1 to 10,000 - `skip` — optional, defaults to 0 - `fields` — comma-separated projection, e.g. `timestamp,asset_id,data.hole_depth` - `include_count` — adds the total to the `Total` response header Encode `query` and `sort` through your HTTP library's parameter encoder, not by hand. For large exports use timestamp-cursor paging, not unbounded skip: sort ascending, take up to 10,000, record the last timestamp, then add `timestamp: {"$gt": last}` to the next query and stop on an empty array. ## Writing data `POST /api/v1/data/{provider}/{dataset}/` accepts 1 to 1,000 records per request. WARNINGS an agent must respect: - There is NO idempotency mechanism. No Idempotency-Key header, no request key, no replay window. A timed-out POST cannot be safely retried; retrying may duplicate up to 1,000 records. - DELETE on the collection form removes MANY records matching a query in a single call, and there is no restore, trash or undo operation anywhere in the API. - `GET /api/v1/data/{provider}/{dataset}/count/` is the safest rehearsal available: count what a query matches before running the same query as a delete. ## Limits - No rate limits are published. 429 is documented as a status to back off from, but there is no published number, window, scope, or any RateLimit-* / Retry-After response header. - Read limit 1-10,000 records. Insert batch 1-1,000 records. A platform request timeout exists but its duration is not published. - Retry transient failures with exponential backoff and jitter. Do NOT retry 400, 401, 403 or 422 without changing the request. ## Errors Not RFC 9457. The Data API returns `{"code": , "message": }`. The Platform API declares 400/401/403/404/409/412/422 status codes but attaches no response schema to any of them. Unrouted paths on api.corva.ai return `{"status":"Route Not Found"}`. ## Real-time Corva is a real-time platform, but its event surface is in-platform: - `socketClient` from `@corva/ui` subscribes a Dev Center frontend app to new dataset records. - Dev Center stream apps are invoked per arriving record. - Producing IS a contract operation: `POST /api/v1/subscriptions/{provider}/{dataset}/{asset_id}/` and `POST /api/v1/message_producer/`. There is no AsyncAPI document and no outbound webhook mechanism. An external system cannot subscribe to Corva events without deploying an app inside Corva Dev Center. ## SDKs - `corva-sdk` (PyPI, 2.1.1, 2026-01-15) — Python Dev Center apps: stream, scheduled, task and followable app types. https://pypi.org/project/corva-sdk/ - `@corva/ui` (npm, 3.74.3, 2026-09-03) — frontend components plus the authenticated clients corvaAPI, corvaDataAPI and socketClient. - `@corva/create-app` (npm, 0.123.0, 2026-08-28) — scaffolding CLI for new Dev Center apps. - `@corva/node-sdk` (npm, 8.5.0, 2023-12-05) — Node backend apps. NOTE: last stable release was December 2023; the Python SDK is the actively maintained backend path. ## Documentation - API overview: https://dc-docs.corva.ai/docs/API/overview - Choose the right API: https://dc-docs.corva.ai/docs/API/choose-the-right-api - Authentication: https://dc-docs.corva.ai/docs/API/authentication - Quickstart: https://dc-docs.corva.ai/docs/API/quickstart - Filtering, sorting, pagination: https://dc-docs.corva.ai/docs/API/Core%20Concepts/query-controls - Limits and performance: https://dc-docs.corva.ai/docs/API/Core%20Concepts/limits-and-performance - Platform API reference: https://dc-docs.corva.ai/docs/API/API%20Reference/platform-api - Data API reference: https://dc-docs.corva.ai/docs/API/API%20Reference/data-api - Dev Center intro: https://dc-docs.corva.ai/docs/intro - Community: https://community.corva.ai/ - Status: https://status.corva.ai/ (machine-readable at /api/v2/summary.json) - GitHub: https://github.com/corva-ai Note: app.corva.ai/docs/* answers HTTP 200 but serves a login-gated SPA shell. The readable documentation is on dc-docs.corva.ai. ## Access There is no public pricing, no free tier, no trial and no self-serve signup. Corva sells through enterprise agreements and AWS Marketplace private offers. The entry point is https://www.corva.ai/schedule-a-demo.