# Galatea Bio > Galatea Bio is a Miami Lakes, Florida genomics company operating a CLIA-CMS certified, > CAP-accredited high-complexity clinical laboratory and the Biobank of the Americas, working to > close the ancestry gap in genomic medicine. Its developer surface is the Octopod Ancestry API, a > REST API for uploading genomic source files, running named analysis models including the > StrataRisk polygenic risk score, and retrieving ancestry, PRS, JSON and PDF report results. Generated: 2026-08-16 Method: generated Source: api.galatea.bio published Swagger document, docs.galatea.bio, github.com/GalateaBio Note: Galatea Bio does not publish an llms.txt of its own. /llms.txt returns the single-page-app shell on galatea.bio, app.galatea.bio and docs.galatea.bio, and 404 on api.galatea.bio. This file was generated by API Evangelist from the provider's public artifacts. ## API - [Octopod Ancestry API](https://docs.galatea.bio/): REST API, Swagger 2.0, 99 operations across 79 paths. Production base URL https://api.galatea.bio/api/v1, sandbox https://api.sandbox.galatea.bio/api/v1. - [Live Swagger UI](https://api.galatea.bio/swagger/): drf-yasg console rendering the full operation set. - [Machine-readable spec](https://api.galatea.bio/swagger/?format=openapi): Swagger 2.0 JSON, served live from the running application. ## Docs - [API documentation](https://docs.galatea.bio/): overview, environment table, API reference, recipes and error reference on one page. - [API reference](https://docs.galatea.bio/#api-reference-contents): auth, users, data and exec endpoint reference with curl and Python examples. - [Recipes](https://docs.galatea.bio/#recipes-contents): authentication, client install, file upload via API and SFTP, order submission, result and PDF retrieval, webhook handling. - [Errors](https://docs.galatea.bio/#errors-contents): status-code reference - 400, 401, 403, 404, 405, 406, 422, 500, 503. - [Webhook handling](https://docs.galatea.bio/#recipe-handling-webhooks-deliveries): HMAC-SHA256 signature verification recipe. ## Client libraries - [octopod-cli](https://github.com/GalateaBio/octopod-cli): first-party Python wrapper and `octo` CLI, MIT licensed. Install from git; the documented `pip install octopod` resolves to an unrelated PyPI project. - [GitHub organization](https://github.com/GalateaBio): Galatea Bio's public repositories. ## Authentication - Bearer token in the `Authorization` header, applied to every operation. - Two credential modes: a long-lived organization API key, or a short-lived access token from `POST /users/auth` renewed with `POST /users/refresh`. - Multi-factor confirmation via `POST /users/confirm` with an `mfa_session_id` and numeric code. - SFTP transfers authenticate separately with SSH keys managed through the API. - No OAuth 2.0, no OpenID Connect, no published scopes. ## Conventions - Pagination: `page` and `page_size` query parameters; `count` / `next` / `previous` / `results` envelope. - Identifiers: bare UUID v4 with no type prefix. - Errors: flat `{"detail": "..."}` JSON. Not RFC 9457 problem+json. - Versioning: URI path, `/api/v1`. No deprecation or Sunset header support. - Idempotency: not supported. Order submission is not retry-safe and is billable. - Rate limits: none published; no `429` and no rate-limit headers. ## Core workflow 1. Upload a source file — `POST /data/files/upload` (under 50 MB) or SFTP for any size. 2. Wait for validation — `source_file_validation_completed` webhook, or poll `GET /data/files`. 3. Submit an order — `POST /exec/orders` with a `source_file_id` and a `model_name`. 4. Wait for completion — `order_moved_to_completed_state` webhook, or poll `GET /exec/orders`. 5. Download results — `GET /data/results/{order_id}/download` or `/json`, and PDF reports via `/pdf_report`. ## Events - `source_file_validation_completed` — a source file finished validation. - `order_moved_to_completed_state` — an order reached Completed or Failed. - Signed with `X-Octopod-Signature`: base64 HMAC-SHA256 over sender host plus raw body. - Endpoints expect an empty HTTP 200 response. ## Company - [Website](https://galatea.bio/) - [Life sciences](https://galatea.bio/life-sciences): sequencing services and the CLIA/CAP laboratory. - [About](https://galatea.bio/about-us) and [leadership](https://galatea.bio/about-us/leadership) - [Publications](https://galatea.bio/about-us/publications) and [news](https://galatea.bio/about-us/news) - [Investor relations](https://galatea.bio/investor-relations) - [Biobank of the Americas](https://bbofa.org/) - [Console login](https://app.galatea.bio/) - Contact: info@galatea.bio ## API Evangelist artifacts - [OpenAPI](openapi/galatea-bio-octopod-openapi.yml) - [Authentication](authentication/galatea-bio-authentication.yml) - [Conventions](conventions/galatea-bio-conventions.yml) - [Error catalog](errors/galatea-bio-problem-types.yml) - [Data model](data-model/galatea-bio-data-model.yml) - [Webhooks](asyncapi/galatea-bio-octopod-webhooks.yml) - [Sandbox](sandbox/galatea-bio-sandbox.yml) - [Lifecycle](lifecycle/galatea-bio-lifecycle.yml) - [Conformance](conformance/galatea-bio-conformance.yml) - [Packages](packages/galatea-bio-packages.yml) - [CLI](cli/galatea-bio-cli.yml) - [Agent skills](skills/_index.yml) - [Rate limits](rate-limits/galatea-bio-rate-limits.yml) - [Plans and pricing](plans/galatea-bio-plans-pricing.yml) - [Agentic access](agentic-access/galatea-bio-agentic-access.yml) ## Not published - No MCP server, no A2A agent card, no `/.well-known/` documents, no `security.txt`. - No AsyncAPI document (the webhook surface is documented in prose). - No status page, no changelog, no SLA, no public pricing. - No public terms of service or privacy policy.