The modules that keep the platform running rather than serve a business domain — UsageModule, MonitoringModule, ConnectModule, UpstreamModule and K8sManagementModule. Most orgs never call these directly; the ones that do are billing, ops and integration teams.
Usage
Metering is off by default and governed by two environment flags:
| Flag | Effect |
|---|---|
ENABLE_TOKENIZATION | The master switch. Unless it is true, nothing is metered or deducted |
TRACK_USAGE_WHEN_DISABLED | Records usage for analytics without deducting anything |
Both are logged at boot, so the startup output tells you which mode a deployment is in.
What gets metered
Only endpoints with a declared cost. Everything else passes through untouched:
| Endpoint | Cost |
|---|---|
/ai/chat | 2 × multiplier |
/ai/agent/chat | 3 × multiplier |
/ai/agent/stream | 5 × multiplier |
The multiplier is 0.0001, so cost is a dollar figure derived from complexity. API key operations — update, delete, regenerate — are recorded at zero.
How a request is charged
UsageMiddleware runs on the way in and settles on the way out:
- No
orgidheader → pass through. Metering is per organization. - Endpoint has no declared cost → pass through.
- Tokenization off, tracking on → record usage with
trackingOnly: trueand deduct nothing. - Tokenization off → pass through.
- Org has a subscription → pass through without deduction. Subscriptions are not metered.
- No subscription, insufficient balance →
402withrequiredandavailable. - Otherwise the response is intercepted, and only a 2xx deducts tokens and records usage.
Two consequences worth knowing: a failed request is never charged, and deduction happens asynchronously after the response — an error while deducting is logged, not surfaced to the caller. The middleware also fails open; if it throws, the request proceeds.
Balances and history
/usage/balanceJWT/usage/statsJWT/usage/:orgId/current/:type?JWT/usage/history/:type?JWT/usage/giftJWTgift credits an org without a payment — trials, goodwill and support credits.
/usage/endpointsJWT/usage/endpointsJWT/usage/endpoints/:endpointJWTThe cost table is editable at runtime, so a new metered endpoint does not need a deploy.
/usage/ai/modelsJWT/usage/ai/provider-keyJWT/usage/ai/chargeJWTai/charge books AI spend that did not arrive through a metered HTTP endpoint — background jobs and agent runs.
Service pricing
Per-service rates, separate from AI token costs.
/service-pricing/listJWT/service-pricing/activeJWT/service-pricing/catalogJWT/service-pricing/:serviceJWT/service-pricing/check-balance/:serviceJWT/service-pricingJWT/service-pricing/initializeJWT/service-pricing/:nameJWT/service-pricing/:nameJWT/service-pricing/allJWTcheck-balance/:service is the pre-flight an app should make before starting something billable — buying a phone number, sending a broadcast.
Datatypes: usage, service_pricing, wallet, wallet_transaction.
Monitoring
Platform health. These endpoints are public — they back status pages and external probes, so treat what they expose accordingly.
/monitoring/healthNo auth/monitoring/overviewNo auth/monitoring/historicalNo auth/monitoring/system-metricsNo auth/monitoring/alertsNo auth/monitoring/alert-notificationsNo auth/monitoring/queuesNo auth/monitoring/queues/:queueNameNo authQueue depth is the first place to look when automations, escalations or broadcasts run late — all three are queue-driven.
/monitoring/usageNo auth/monitoring/user-activityNo auth/monitoring/web-activityNo auth/monitoring/company-creationNo auth/monitoring/domain-mappingsNo authAnalytics, stats and overviews
One module, AnalyticsModule (src/analytics), serves three route families.
Analytics dashboards — per-surface aggregates, one endpoint each. Every one takes startDate / endDate; GET /analytics takes type (website, blog, workflow, storefront, tickets, leads, automation, users, email) or returns them all.
/analyticsJWT/analytics/websiteJWT/analytics/blogJWT/analytics/workflowJWT/analytics/storefrontJWT/analytics/storefront/ordersJWT/analytics/ticketsJWT/analytics/attributionJWT/analytics/leadsJWT/analytics/automationJWT/analytics/usersJWT/analytics/emailJWT/analytics/filter-optionsJWT/analytics/live-viewJWT/analytics/live-view/:deviceId/journeyJWT/analytics/exportJWTAggregations run against a secondary read and are briefly cached. live-view is visitors in the last minutes (default 15); attribution is revenue by source, medium and campaign.
Engagement stats — /stats/:datatype/:id/{like,dislike,bookmark,follow,favorite,rating,reaction,view,share}, GET /stats/:datatype/:id, /stats/by-resource/… and /stats/by-customer/…. See Engagement and search.
Studio overviews — the figures behind each Studio section's dashboard, computed on the server so the screen only renders them.
/studio-overview/:sectionJWTsection is one of home, account, config, database, build-studio, dam, crm, store, events, community, finance, logistics, ai-automation; anything else is 404. The response is { section, generatedAt, … }.
Connect
Third-party credentials, OAuth handshakes and inbound webhooks. Every vendor callback lands here.
/connect/webhook/:vendor/:serviceId?No auth/connect/webhook/:vendor/:serviceId?No auth/connect/oauth2callback/:vendorNo authPublic by necessity — the caller is a vendor, not a user — so each vendor adapter verifies its own signature.
/connect/automation/:id/:stepId/:entity/:activity/No auth/connect/automation/:id/:stepId/:entity/:activity/No authThe resume path for automations parked waiting on an external event.
Vendor adapters cover payments (Stripe, PayPal, Helcim), email (Mailgun, SendGrid, SES), telephony (Twilio), shipping (EasyPost), design (Figma), and the social networks (Facebook, Instagram via Threads, LinkedIn, X, TikTok, Pinterest, Mastodon, WhatsApp, Google).
Upstream
Calls out to those integrations, with configuration and a test harness.
/upstream/integration-types/:type?JWT/upstream/integration-use-cases/:useCaseJWT/upstream/get-config/:type?/:configId?JWT/upstream/active/:type?JWT/upstream/active/detail/:id?JWT/upstream/get-integrationJWT/upstream/save-integrationJWT/upstream/shutdown/:idJWT/upstream/call/:integration/:operationJWT/upstream/call/:integration/:operationJWT/upstream/service/:serviceName/:operationJWT/upstream/service/:serviceName/:operationJWT/upstream/test/:integration/:operationJWTtest exercises an operation with the saved credentials without committing the result — the way to validate a connection before an automation depends on it.
Cluster management
Namespace and workload control for tenant infrastructure. Destructive by design; restrict it accordingly.
/k8/namespacesJWT/k8/namespaces/:namespaceNameJWT/k8/namespaces/:namespaceName/podsJWT/k8/check-status/:namespace/:kind/:resourceJWT/k8/apply-serviceJWT/k8/scale-upJWT/k8/scale-downJWT/k8/cleanup-resourcesJWT/k8/delete-service/:namespace/:kind/:nameJWT/k8/namespaces/:nameJWTscale-down to zero is how idle tenant environments stop costing anything; apply-service is what brings one back.
Related
- Usage and cost — what AI calls are metered on
- Architecture — where these modules sit in the request pipeline
- Billing — plans, balances and invoices
- Integrations — connecting a vendor end to end