# H2O.ai > H2O.ai is an open-source artificial-intelligence and machine-learning company. Its platform > spans H2O-3 (a distributed, in-memory ML engine), H2O Driverless AI (automatic machine > learning), H2O MLOps (model deployment, scoring and monitoring), H2O Wave (a Python/R > framework for realtime AI apps), H2O LLM Studio, and Enterprise h2oGPTe (a private > generative-AI, RAG and agent platform). Two machine-readable REST contracts are published: > Enterprise h2oGPTe (OpenAPI 3.0.1, 422 operations, 24 tags) and H2O MLOps Scoring > (OpenAPI 3.0.0, 7 operations). H2O.ai also ships a first-party MCP server that projects the > h2oGPTe REST API onto agent tools. This file was generated by API Evangelist from the public H2O.ai surface on 2026-08-04. H2O.ai does not publish an llms.txt of its own (probed h2o.ai/llms.txt 404, docs.h2o.ai/llms.txt 404). ## APIs - [Enterprise h2oGPTe REST API](https://docs.h2o.ai/enterprise-h2ogpte/rest-api): Collections, document ingestion, chat, agents, AI assistants, extractors, GraphRAG, guardrails, memory blocks, models, prompt templates, jobs, scheduled tasks, permissions, API keys and secrets. Base URL `https://h2ogpte.genai.h2o.ai/api/v1`. Auth: `Authorization: Bearer sk-...`. - [H2O MLOps Scoring REST API](https://docs.h2o.ai/mlops/model-scoring/mlops-scoring-rest-api): runtime scoring for a deployed model — model id, schema, sample request, capabilities, row scoring, media scoring and Shapley contributions. Host is per-deployment. - [h2oGPTe MCP Server](https://github.com/h2oai/h2ogpte-mcp-server): first-party local stdio MCP proxy over the h2oGPTe REST API. One tool per REST operationId. ## Specs - [h2oGPTe OpenAPI 3.0.1](https://h2ogpte.genai.h2o.ai/api-spec.yaml) - [MLOps Scoring OpenAPI 3.0.0](https://docs.h2o.ai/mlops/model-scoring/mlops-scoring-rest-api) - [h2oGPTe Swagger UI](https://h2ogpte.genai.h2o.ai/swagger-ui/) — authenticated, live requests ## Docs - [H2O.ai documentation hub](https://docs.h2o.ai/) - [Enterprise h2oGPTe docs](https://docs.h2o.ai/enterprise-h2ogpte/) - [Enterprise h2oGPTe get started](https://docs.h2o.ai/enterprise-h2ogpte/get-started) - [API keys guide](https://docs.h2o.ai/enterprise-h2ogpte/guide/apis) - [h2oGPTe changelog](https://docs.h2o.ai/enterprise-h2ogpte/changelog) - [h2oGPTe major releases](https://docs.h2o.ai/enterprise-h2ogpte/releases) - [H2O MLOps docs](https://docs.h2o.ai/mlops/) - [H2O AI Cloud docs](https://docs.h2o.ai/haic-documentation/) - [H2O Wave docs](https://wave.h2o.ai/) ## SDKs and CLIs - Python: `h2o`, `h2ogpte`, `h2o-mlops`, `driverlessai`, `h2o-wave`, `h2o-lightwave`, `h2o-authn`, `h2o-cloud-discovery`, `h2o-drive`, `h2o-engine-manager`, `h2o-notebook`, `h2o-secure-store`, `h2o-featurestore`, `h2osteam`, `h2ogpte-mcp-server` (PyPI) - JavaScript: `h2ogpte`, `h2o-wave` (npm) - R: `h2o` (CRAN) - Java: `ai.h2o:*` — 97 artifacts on Maven Central, including `h2o-core` and `mojo2-runtime-api` - CLI: `wave` (from `pip install h2o-wave`) — https://wave.h2o.ai/docs/cli ## Operations - [Status page](https://h2oai.statuspage.io/) — H2O AI Cloud, Atlassian Statuspage - [Support](https://support.h2o.ai/) - [Security](https://h2o.ai/security/) and [report a vulnerability](https://h2o.ai/security/report-vulnerability) - [Trust Center](https://trust.h2o.ai/) — SOC 2 Type 2, FedRAMP High, IRAP, HITECH - [Blog](https://h2o.ai/blog/) - [GitHub organization](https://github.com/h2oai) - [Sign up (freemium tier)](https://genai.h2o.ai/appstore) - [Terms of use](https://h2o.ai/legal/terms-of-use/) · [Privacy](https://h2o.ai/legal/privacy/) ## Known gaps An agent integrating with these APIs should know what is NOT published: - No idempotency key — retrying a POST creates a duplicate. - Errors use a vendor `{code, message}` envelope, not RFC 9457 problem details; no error-code registry. - Rate limiting exists (h2oGPTe 1.7.0) but no limit values, header names or Retry-After contract are documented. - No deprecation or version-support policy; no Sunset/Deprecation headers. - No webhooks and no AsyncAPI — long-running work is job-polling (28 job operations). - No /.well-known/security.txt, no api-catalog, no A2A agent card on any host. - No test-mode key or sandbox host; the interactive Swagger UI hits the live tenant.