# OPAQUE > OPAQUE Systems, Inc. is a confidential-AI platform company. The OPAQUE Confidential AI Platform > runs agentic workflows, retrieval-augmented generation and analytics jobs on sensitive data > inside hardware trusted execution environments, with attested TLS between components, signed > attestation reports and tamper-evident audit logs. It ships in a hybrid architecture: an > OPAQUE-hosted control plane handles users, workspaces, job metadata, notifications, audit > logging and key management, while the data plane, the client/API pod and all encrypted storage > run inside the customer's own cloud environment. Generated by API Evangelist on 2026-08-04 from OPAQUE's public documentation and its published OpenAPI 3.0.3 specification. OPAQUE does not publish an llms.txt of its own — https://docs.opaque.co/llms.txt and https://www.opaque.co/llms.txt both return 404. ## APIs - [OPAQUE Platform REST API](https://docs.opaque.co/en/latest/api_reference/rest_api/): 65 paths, 82 operations across workspaces, datasets, jobs, job runs, workflows, asset configs, users and organizations. OpenAPI 3.0.3, info.version 2.5. - Base URL is per-deployment: `https://api./`. OPAQUE serves the web UI and the REST API from inside the customer's own environment, so there is no shared production host. The specification declares only `http://localhost:5001/`. ## Specs - [OpenAPI 3.0.3](https://docs.opaque.co/en/latest/api_reference/endpoints/V1/reference/Opaque-UI.yaml) — the source document, served to the Swagger UI iframe on the API reference page. - Model schemas: the spec's `components.schemas` are external `$ref`s to `https://docs.opaque.co/en/latest/api_reference/endpoints/V1/models/*.yaml` (User, Workspace, Datum, Job, JobRun, OrganizationData, AssetConfig and 13 more). They resolve, but only if you fetch them separately. ## Docs - [Documentation home](https://docs.opaque.co/en/latest/) - [API overview](https://docs.opaque.co/en/latest/public_guide/developers/rest_api/) - [Authentication](https://docs.opaque.co/en/latest/public_guide/developers/rest_api/authentication/) - [Response codes and errors](https://docs.opaque.co/en/latest/public_guide/developers/rest_api/response_codes_errors/) - [Python SDK reference](https://docs.opaque.co/en/latest/api_reference/python_sdk_reference/) - [Invoking workflows](https://docs.opaque.co/en/latest/public_guide/users/workflows/invoking_workflows/) - [Deployment architecture](https://docs.opaque.co/en/latest/public_guide/deployment/hybrid_deployment/) - [Versioning](https://docs.opaque.co/en/latest/public_guide/users/admins/versioning/) - [Release notes](https://docs.opaque.co/en/latest/release_notes/) - [Support](https://docs.opaque.co/en/latest/support/) ## Authentication Three credentials, all per user, all issued after SSO (Microsoft Entra ID or Okta): - **API key** — base64, copied from *API Keys* in the web app, valid six months. Decoding it yields `refresh_token` and `user_identity_secret`. - **Session token** — a JWT with a **10-minute** lifetime, obtained from `POST /{version}/auth/refresh-token`, sent as `Authorization: Bearer ` (or as the `sessionTokenCookie` cookie for browser calls). - **User identity secret** — sent as the `userIdentitySecret` cookie, required for cryptographic and sensitive-data operations such as data upload and job-result retrieval. There is no OAuth flow and there are no scopes. Authorization is by organization and workspace role. ## Conventions - Resource-oriented REST, JSON in and out; `multipart/form-data` for uploads, `text/plain` for logs. - Version is a path parameter: `/{version}/...`. - Every resource is addressed by a bare UUID — no type prefixes. - Errors carry RFC 7807/9457 field names (`type`, `title`, `status`, `detail`) over `application/json`, with `type` set to `about:blank` or `exception`. - **No idempotency keys. No pagination. No rate-limit headers. No request-id tracing header.** Write operations are not documented as retry-safe. - Jobs and workflows are approval-gated state machines; most `400`s are state violations, and the `detail` field names the state that was required. ## Events None. OPAQUE delivers job-completion and similar alerts as in-platform notifications from the control plane. There are no outbound webhooks and no AsyncAPI document. ## MCP OPAQUE **consumes** MCP; it does not serve it. The MCP Tool node lets an Agent node in tool mode call external MCP tools, with runtime context mapping onto parameters read from the target tool's OpenAPI spec. "Confidential MCP" runs those tool calls inside the confidential runtime and is open-sourced at https://github.com/agentrust-io (`cmcp`). There is no public OPAQUE MCP endpoint. ## SDKs - **Python SDK** — first-party, documented, and **not on PyPI**. It is distributed as a ZIP from your OPAQUE contact, version-matched to your deployment (`pip install opaque-.tar.gz`, Python 3.10+). Import `from opaque.workflow import WorkflowService`. The PyPI project named `opaque` is unrelated. - [opaqueprompts](https://pypi.org/project/opaqueprompts/) — first-party but for OpaquePrompts, an earlier product, not the platform. - GitHub org: https://github.com/opaque-systems ## Security and compliance - SOC 2 Type 2 (Security, Confidentiality, Privacy), audited by BARR Advisory, announced 2023-01-30. - No `/.well-known/security.txt`, no published vulnerability-disclosure policy, no bug bounty and no trust center were found on any OPAQUE host. - `opaque.co`: DNSSEC enabled, SPF and DMARC present (policy `quarantine`), no CAA records. `www.opaque.co` sends HSTS with a one-year max-age; `docs.opaque.co` does not. ## Company - [Website](https://www.opaque.co/) - [Resources and articles](https://www.opaque.co/resources) - [Terms of service](https://www.opaque.co/terms-of-service) · [Privacy policy](https://www.opaque.co/privacy-policy) - Contact: hello@opaque.co (general), support@opaque.co (account and workspace access) - No public pricing page and no self-serve sign-up. Access is through a demo request. ## Profile - API Evangelist profile: https://github.com/api-evangelist/opaque