← All docs

API & webhooks

Trigger flights and receive signed events from your systems.

All guides

Personal access tokens

Create scoped tokens in Dashboard → Settings → API keys. Scopes include flights:read, flights:write, runs:read, runs:execute, accounts:read, mcp:read and mcp:manage. Tokens are shown once and stored hashed.

Calling the API

Send Authorization: Bearer rp_… with every request to https://api.runpilots.com. Create a run with POST /v1/flights/:id/run, poll GET /v1/runs/:id, or list step logs with GET /v1/runs/:id/steps.

Webhook events

Register endpoints for run.succeeded, run.failed, run.awaiting_approval, approval.resolved and flight.schedule_missed. Each delivery is signed with HMAC-SHA256 over the raw body: X-Run Pilots-Signature: t=…,v1=…

Reliability

Deliveries retry with exponential backoff for 24 hours. Verify signatures with a five-minute timestamp tolerance and make handlers idempotent using the event id.

Ready when you are

Put this guide to work

Connect an account and run your first scheduled flight tonight.

7-day refund · Cancel anytime · No API keys · Encrypted by default