# Hilbert's AI > AI-native growth infrastructure for B2C companies, backed by a16z. Hilbert unifies > product, marketing and finance data into one source of truth and layers agentic > automation on top across four stages — Detect, Reason, Act, Optimize — accessed through > a natural-language interface rather than dashboards. Delivered as a hosted application > at app.hilberts.ai. There is no public developer program: no portal, no documentation > site, no SDKs, no CLI, no MCP server and no published pricing. The application backend > does serve a publicly reachable OpenAPI 3.0.0 document, but it declares zero operations. This file was generated by API Evangelist from the public Hilbert's AI surface on 2026-08-13. Hilbert does not publish an llms.txt of its own; https://hilberts.ai/llms.txt returns HTTP 404. ## API - [Hilbert's Program API (Swagger UI)](https://app-api.hilberts.ai/api-docs): The only API reference Hilbert publishes. Serves an OpenAPI 3.0.0 document with populated components (2 security schemes, 8 schemas) and an EMPTY paths object — no operation is documented, so nothing in this contract is callable as published. - Production base URL: `https://app-api.hilberts.ai/api/v1` — observed as the configured API base and Auth0 audience in the public app.hilberts.ai JavaScript bundle. The spec's own servers[] block still carries the placeholder `http://localhost:3000/api/v1`. - Authentication: bearer JWT issued by the Auth0 tenant `hilbert-app.us.auth0.com` (audience `https://app-api.hilberts.ai`), or an `x-api-key` header for server-to-server calls. No key-issuance path is documented. - Rate limit: 1200 requests per rolling 60-second window, emitted at runtime as `x-ratelimit-limit` / `x-ratelimit-remaining` / `x-ratelimit-reset` (unix epoch). Documented nowhere; observed by probe. ## Specs and artifacts - [OpenAPI (refined)](openapi/hilberts-ai-program-api-openapi.yml) - [OpenAPI (verbatim as served)](openapi/_original/hilberts-ai-program-api-openapi.json) - [Overlay of API Evangelist enhancements](overlays/hilberts-ai-program-api-overlay.yaml) - [Authentication profile](authentication/hilberts-ai-authentication.yml) - [OAuth / OIDC scopes](scopes/hilberts-ai-scopes.yml) - [API conventions](conventions/hilberts-ai-conventions.yml) - [Data model](data-model/hilberts-ai-data-model.yml) - [Error catalog](errors/hilberts-ai-problem-types.yml) - [Rate limits](rate-limits/hilberts-ai-rate-limits.yml) - [Lifecycle](lifecycle/hilberts-ai-lifecycle.yml) - [Conformance](conformance/hilberts-ai-conformance.yml) - [Plans and pricing](plans/hilberts-ai-plans-pricing.yml) - [Well-known probe](well-known/hilberts-ai-well-known.yml) - [Domain security](security/hilberts-ai-domain-security.yml) - [Packages](packages/hilberts-ai-packages.yml) ## Product - [Hilbert's AI](https://hilberts.ai): Homepage. - [Integrations](https://hilberts.ai/integrations): Prebuilt connectors — Meta, Google, Pinterest, Snapchat and Reddit ads; Google Analytics 4 and Triple Whale analytics; Klaviyo and Braze CRM. Data is pulled in to feed the customer intelligence layer and predicted segments are pushed back out for targeting and retention. - [Growth Hub](https://hilberts.ai/growth-hub): Playbooks covering acquisition, pricing, discounting, AOV, financial health, operations, product and user behavior. - [Hilbert Space](https://hilberts.ai/hilbert-space): Podcast series. - [Startup Program](https://hilberts.ai/startup-program) - [About](https://hilberts.ai/about-us) - [Careers](https://hilberts.ai/careers) ## Access - [Book a demo](https://hilberts.ai/book-a-demo): The only way in. There is no self-serve signup and no published pricing — https://hilberts.ai/pricing returns HTTP 404. - [Application login](https://app.hilberts.ai/) - [Terms of service](https://hilberts.ai/terms-of-service) - [Privacy policy](https://hilberts.ai/privacy-policy) ## What Hilbert does not publish - No developer portal, documentation site, getting-started guide or API reference beyond the Swagger UI above. - No operations in its OpenAPI (`paths: {}`). - No SDKs or client libraries in any registry; no CLI. - No MCP server and no A2A agent card — `/.well-known/agent-card.json` and `/.well-known/agent.json` return 404 on hilberts.ai and app-api.hilberts.ai. - No webhooks, events or AsyncAPI. - No `/.well-known/security.txt`, status page, changelog, deprecation policy or SLA. - No trust center. SOC 2 is stated on the homepage with no report, type, auditor or date.