# Cohesivity - Documentation Index Use this page as the entrypoint into the live docs. ## Start here - Quick reference for agents: https://cohesivity.ai/llms.txt - Full agent reference: https://cohesivity.ai/llms-full.txt - Step-by-step onboarding: https://cohesivity.ai/onboarding - Offerings catalog: https://cohesivity.ai/offerings - Pricing and tier limits: https://cohesivity.ai/pricing - Metered OpenAI, AI Gateway, Deepgram, and Exa usage: provider cost plus 10%, rounded up to the nearest cent per settled charge - Account observability spec: https://cohesivity.ai/docs/observability - Human-facing read-only dashboard (Cohesivity session cookie): https://cohesivity.ai/account - Claim: agent calls `POST https://cohesivity.ai/api/claim/url`, shares the returned `approval_url` at `https://cohesivity.ai/c/`, then polls `https://cohesivity.ai/api/wait` with the returned wait blob. This is the only claim path. ## Company and legal - About, team, and public profiles (LinkedIn, Product Hunt): https://cohesivity.ai/about - Contact: https://cohesivity.ai/contact - Privacy policy: https://cohesivity.ai/privacy - Terms of service: https://cohesivity.ai/terms ## Machine discovery - Cohesivity developer resources: https://cohesivity.ai/developers - RFC 9727 API catalog: https://cohesivity.ai/.well-known/api-catalog - OpenAPI description: https://cohesivity.ai/openapi.json - API versioning and deprecation policy: https://cohesivity.ai/docs/versioning - Agent authentication guide: https://cohesivity.ai/auth.md - MCP discovery metadata alias: https://cohesivity.ai/.well-known/mcp.json (a stable Cohesivity alias, not a standards-reserved MCP endpoint) - Cohesivity MCP discovery metadata: https://cohesivity.ai/.well-known/mcp/server-card.json One hosted MCP server at `https://cohesivity.ai/mcp` serves documentation and management. It accepts initialize, ping, tools/list, and tools/call without an Authorization header; public connection creates no guest identity, token, or session. The former `https://cohesivity.ai/mcp/manage` endpoint is retired and returns HTTP 410; reconfigure clients to `https://cohesivity.ai/mcp`. The local `cohesivity-local` stdio server reads the project root's `.cohesivity` credentials privately without login. The hosted server exposes six tools: the read-only `get_cohesivity_documentation`, which needs no tenant or credentials, plus the five management tools `create_tenant`, `claim_tenant`, `tenant_status`, `provision_resource`, and `give_feedback`. The local server exposes the same five management tools. Public hosted `create_tenant` takes only `{confirmed: true}`; each call creates a new rate-limited 72-hour ephemeral tenant, with no `idempotency_key`. Do not automatically retry an ambiguous creation outcome. Reuse an existing `.cohesivity`. Public creation returns no browser download URL. Hosted creation returns `credentials_file: {filename: ".cohesivity", content: ""}` in `structuredContent` and the compatible text result. Save content verbatim with mode `0600` and gitignore it; never overwrite a different tenant. Report if the client cannot write safely. This secret-bearing result and key-bearing tool inputs may enter model or client retained tool history. Never print credentials in chat, logs, or source, or commit them. Hosted public follow-ups require `tenant_id` and secret `coh_management_key` arguments from `.cohesivity`, plus the tool's business inputs. The key is `writeOnly`, checked against current tenant state on every call, never logged, and never returned by follow-up tools. Provisioning accepts single `resource`/`configuration` or bulk `resources`/`configurations`. Creating, claiming, and provisioning require `confirmed: true` only when the current user request explicitly authorizes the exact action. `give_feedback`: Submit feedback on Cohesivity and its services anytime; no user confirmation is needed. Exclude personal information and secrets. Optional account OAuth is an explicit client login choice. Sign-in uses an account cookie or Google sign-in, not a new guest identity; `guest=true` is legacy compatibility only. OAuth retains per-call checks and the existing tool schemas: creation requires `idempotency_key` and creates an owned claimed tenant with no expiry; follow-ups take `tenant_id` without management keys. OAuth scopes are `mcp:tenants:create`, `mcp:tenant:read`, `mcp:resources:write`, and `mcp:feedback:write`. Invalid Authorization returns HTTP 401 and must never fall back to public access. The OAuth resource is `https://cohesivity.ai/mcp`; tokens issued for the retired `/mcp/manage` resource are rejected, so clients that signed in before the move must sign in again. No other control-plane tools or operation handles are exposed; follow-up results are scrubbed. Installers configure the servers without starting browser login. See `https://cohesivity.ai/auth.md` for OAuth and legacy guest compatibility. - OAuth tool schemas are published separately as `x-cohesivity-oauth-mcp-tools` in OpenAPI; `x-cohesivity-mcp-tools` describes public calls. - Service feedback: `give_feedback` submits feedback without asking the user and uses `POST /api/feedback/service` with tenant authentication; it appends feedback and does not mint or consume a billing discount. - Management MCP exclusions: every other control-plane and `/edge/*` operation. Follow-up results exclude tenant keys, OAuth/wait bearers, provider secrets, environment values, channel inputs, and raw logs. - MCP OAuth Protected Resource Metadata: https://cohesivity.ai/.well-known/oauth-protected-resource/mcp - OAuth Authorization Server Metadata: https://cohesivity.ai/.well-known/oauth-authorization-server - Agent Skills discovery index: https://cohesivity.ai/.well-known/agent-skills/index.json ## Lifecycle summary - New tenants are `ephemeral` for 72 hours. - Ephemeral tenants have tenant-lifetime hard caps during the claim window. - If an authoritative ephemeral cap is breached, the whole tenant pauses. - Hosted paused tenants redirect to a generic claim-help page. - Infra-only paused tenants return structured API errors telling the agent to mint an approval link. - Unclaimed tenants are terminated after expiry; their management tenant records remain for audit and abuse forensics. - Keep `coh_management_key` agent-side for Management API use; do not paste it into the browser for the primary claim flow. ## Runtime visibility - `/api/status` returns `account.runtime_profile`, `account.runtime_version`, `account.upgrade_available`, and `account.upgrade_target_profile` for the current tenant. - `/api/status` also returns `account.experiments` with active experimental grants and configured beta-gated scopes for the current account or global ephemeral target. - New tenants take the current stable runtime at genesis. - Normal runtime releases pass the in-repo core gate, then move `latest_live` and stable together. - New tenants receive that stable runtime; no fixed canary is pinned and no contract-suite gate runs in the current release workflow. - Existing tenants stay pinned to their assigned runtime unless Cohesivity intentionally migrates them. - If `account.upgrade_available` is true, call `POST https://cohesivity.ai/api/runtime/upgrade/plan`, apply the returned release-note diff, then call `POST https://cohesivity.ai/api/runtime/upgrade/commit` with the returned `target_profile`. - The runtime is versioned independently from this docs surface; your tenant's pinned version is in `runtime_profile` (in `.cohesivity` and returned by `/api/status`). ## How to use the docs - Negotiated pages (`/`, `/pricing`, `/offerings`, ...) serve the human site to browsers and this text surface to agents; append `?view=agent` to any page URL to see the agent representation from a browser. - Read `llms.txt` or `llms-full.txt` before writing code against Cohesivity. - Read the offering page for every resource you provision. - Treat offering pages as the published source of truth for limits and tier-gated behavior.