# Oracle Cloud Infrastructure (OCI) > Oracle's public cloud. A REST control plane of 159 service APIs — compute, networking, object > storage, identity, database, Kubernetes, functions, monitoring, events, notifications and more — > all signed with an RSA API signing key, all versioned by a YYYYMMDD segment in the URL path, and > all described by first-party Swagger 2.0 contracts Oracle publishes at a single indexed location. Generated by the API Evangelist enrichment pipeline on 2026-08-29 from this repository and from Oracle's own published surfaces. Oracle serves no llms.txt of its own: /llms.txt returns 404 on www.oracle.com, docs.oracle.com and cloud.oracle.com (probed 2026-08-29). ## Machine-readable contracts - [OCI API spec index](https://docs.oracle.com/en-us/iaas/api/specs/index.json): the master index — 159 services, each mapped to its per-region endpoints and to a Swagger 2.0 document. This is the starting point for any machine reading OCI. It is NOT at /.well-known/api-catalog. - [Core Services API](https://docs.oracle.com/en-us/iaas/api/specs/): compute, networking, block volume — 490 operations, base path /20160918, host iaas.{region}.oraclecloud.com - Identity and Access Management API: 148 operations, host identity.{region}.oraclecloud.com - Database Service API: 444 operations, host database.{region}.oraclecloud.com - Object Storage Service API: 61 operations, host objectstorage.{region}.oraclecloud.com - Kubernetes Engine API: 50 operations, base path /20180222, host containerengine.{region}.oraclecloud.com - Monitoring API: 18 operations, base path /20180401, host telemetry.{region}.oraclecloud.com - Functions Service API: 17 operations, base path /20181201, host functions.{region}.oraclecloud.com - Events API and Notifications API: base path /20181201 ## How to call it - Authentication: every request must be signed. RSA API signing key (tenancy/user/fingerprint), or instance principals, resource principals, session tokens, workload identity. https://docs.oracle.com/en-us/iaas/Content/API/Concepts/signingrequests.htm - Idempotency: `opc-retry-token` request header, max 64 chars, expires after 24 hours. Accepted by 370 of the 1,268 operations in the harvested contracts — check the operation, do not assume. - Concurrency: `etag` response header, `if-match` request header, 412 NoEtagMatch on conflict. 505 operations accept it. - Pagination: `limit` + `page` query parameters, `opc-next-page` response header. A page can be empty while more results remain — terminate on the ABSENCE of opc-next-page, never on an empty array. Object Storage ListObjects is the exception: `nextStartWith` in the body. - Correlation: every response carries `opc-request-id`. Quote it when reporting a 500 or 503. - Long-running work: 202 Accepted plus `opc-work-request-id`; poll the Work Requests API. - Rate limits: HTTP 429 with `{"code":"TooManyRequests"}`. NO RateLimit-* or Retry-After headers are published. Oracle's stated remediation is exponential back-off from a few seconds to 60. - Errors: flat `{"code","message"}` JSON. Not RFC 9457 problem+json. 32 documented codes at https://docs.oracle.com/en-us/iaas/Content/API/References/apierrors.htm - Versioning: the YYYYMMDD segment in the path IS the version. ## Reversibility — read before you write - Archived object restore: `RestoreObjects`, restored for 24 hours by default, 1–240 hours via the `hours` parameter. The only reversal window Oracle states numerically in a contract. - Retry tokens de-duplicate for 24 hours; that is not an undo. - `RecoverCompartment` restores a deleted compartment; no window is published. - `RestoreAutonomousDatabase` / `RestoreDatabase` do point-in-time restore within configured backup retention; no universal window is published. - `TerminateInstance` is stated to be permanent. `preserveBootVolume` keeps the volume; it does not undo the termination. - There is no dry-run or validate-only mode anywhere in the API. ## Agent surfaces - MCP: Oracle publishes 32 reference MCP servers at https://github.com/oracle/mcp, 27 for OCI. They are LOCAL stdio packages, not a hosted endpoint: `uvx oracle.oci-cloud-mcp-server@latest`. Oracle labels them "not intended for production use". The general server exposes five generic tools (list_oci_clients, find_oci_api, describe_oci_operation, invoke_oci_api, list_client_operations); service servers expose named tools for compute, networking, object storage, identity, monitoring, database and Fusion Applications. - A2A: no agent card is served. /.well-known/agent-card.json and /.well-known/agent.json return 404 on every OCI host and on the docs and console hosts (probed 2026-08-29). - Events: CloudEvents 0.1 envelopes (cloudEventsVersion / eventID / eventTime, plus a mandatory `extensions` object) routed by Events Rules to Notifications, Streaming or Functions. - Webhooks: OCI Notifications HTTPS (Custom URL) subscriptions, with a confirmation handshake. ## Client libraries and tooling - Python `oci` 2.185.0 (2026-08-25) · CLI `oci-cli` 3.91.0 (2026-08-25) - TypeScript `oci-sdk` 2.140.0 (2026-08-25) · Go `oci-go-sdk/v65` v65.124.0 (2026-08-25) - Ruby `oci` 2.24.0 (2026-07-28) · .NET `OCI.DotNetSDK.Core` 145.0.0 - Java `com.oracle.oci.sdk` 3.67.3 on Maven Central (2025-06-24 — roughly 14 months behind the other language lines; Oracle also ships Java builds from the GitHub releases page) - Terraform provider: https://github.com/oracle/terraform-provider-oci ## Operations - Status: https://ocistatus.oraclecloud.com/ (JSON at /api/v2/status.json) - Release notes: https://docs.oracle.com/en-us/iaas/releasenotes/index.htm - Breaking changes and deprecations: https://docs.oracle.com/en-us/iaas/Content/servicechanges.htm — announced on a web page only. No Sunset or Deprecation response headers, and no operation in the contracts is flagged `deprecated`. - Security disclosure: secalert_us@oracle.com, https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting/ Quarterly Critical Patch Updates, third Tuesday of January, April, July, October. No bug bounty. No /.well-known/security.txt is served. - Compliance: https://www.oracle.com/corporate/cloud-compliance/ — SOC 1/2/3, ISO 27001/27017/27018/27701, PCI DSS, HIPAA, HITRUST, FedRAMP, DoD IL, IRAP, C5, ENS, HDS, ISMAP, K-ISMS, MTCS, TISAX, CSA STAR. ## Docs - https://docs.oracle.com/en-us/iaas/Content/home.htm — documentation home - https://docs.oracle.com/en-us/iaas/api/ — API reference and endpoints - https://docs.oracle.com/en-us/iaas/Content/API/Concepts/usingapi.htm — the page that defines every convention above - https://www.oracle.com/cloud/price-list.html — pricing - https://www.oracle.com/cloud/free/ — Always Free tier and 30-day trial credit