The Matflow API
Script your research workflows — upload data, launch runs, poll progress and pull results from your own tooling. The interactive reference with request/response schemas and a try-it console lives at /api-docs.
Get started in four steps
Sign up and generate a key in Settings → API keys. Token-based access uses the same account, permissions and plan limits as the web app.
Settings → API keys → name the integration → Generate. The full key is shown once, at creation.
Keys are hashed server-side and never shown again. Keep the secret in a secret manager or environment variable — never in code, notebooks, or version control.
Send the key as `Authorization: Bearer cf_…`. Rotate or revoke keys in Settings when an integration changes hands.
Keys live in Settings → API keys. Name each key after its integration so it stays recognizable, and revoke it the moment an integration is retired.
Manage API keys →Where the spec lives
Interactive reference with request/response schemas, auth declarations and a try-it console. Alias: /api/docs.
The machine-readable OpenAPI 3.0.3 spec. Versioned alias: /api/v1/openapi.json.
The lightweight group/endpoint catalog that the Developer SDK page renders. It is also what an SDK generator can walk.
Authentication
Session cookies (browser)
What the web app uses. Sign in once; the session cookie authenticates subsequent requests. Same-origin scripts and quick testing are the natural fit. State-changing browser requests carry the app's CSRF protection.
curl -c cookies.txt \
-X POST "$MATFLOW_ORIGIN/api/login" \
-H "Content-Type: application/json" \
-d '{"username":"you","password":"•••"}'Bearer API keys (servers)
Issued from Settings → API keys. Keys are stored hashed server-side and authenticate as your account without a session — the right choice for servers, notebooks and scheduled jobs. Requests with a key bypass the browser CSRF check by design.
curl "$MATFLOW_ORIGIN/api/datasets" \
-H "Authorization: Bearer cf_…"In both examples, replace $MATFLOW_ORIGIN with the origin you are calling — the same origin as the web app (for example, your deployment's host).
Programmatic requests are rate-limited against your tier the same way the web app is — see Tiers and quotas.
What the API exposes
Session status, login/logout, registration and password reset.
Issue, list and revoke programmatic credentials; keys are stored hashed.
Upload, list and manage datasets; preview, quality report, manifest, drift compare, outliers and RO-Crate/OPTIMADE/MDF export.
Extract Excel/CSV/PDF/SDS/image files into evidence-tagged rows, with a human review queue before promotion to a dataset.
Create, poll, cancel and delete runs with progress, phase, artifacts and per-run cost. Idempotency-Key → 409 on retry.
End-to-end runs chaining multiple stages with automatic handoffs.
Ensemble train-and-predict, metrics, explainability, what-if simulation, leaderboard and opt-in tuning.
Auto-select CV leaderboard, Gaussian-process surrogates, model export, and deployed-model scoring (its own X-API-Key surface).
Pareto and Bayesian search, plus factorial, Box–Behnken, Latin-hypercube and mixture designs.
Campaign CRUD, typed entity links and decision-board candidates with approval status.
SDL campaigns, Bayesian step/ingest, durable-loop planning and edge safety events.
Slurm DFT dispatch with status, logs and cluster listing.
QM, MD, docking and FEP engine cards and runs — each result carries its engine and evidence class.
Unified multi-vendor parsers for XRD, GC-MS, UV-Vis, FTIR, NMR, rheology and battery cycler files.
Samples, lineage, microplates, inventory and Opentrons protocol export.
Live rooms, review boards, votes, candidate locks, annotations and an activity feed.
Edge nodes, E-stop interlock and human-in-the-loop action gates.
Phase diagrams, chemical-space projections and structure viewers.
Shareable run reports plus publication dossiers with per-section is_template flags.
Local structure documents plus federated search across public structure providers.
Model cards, featurizers, protocols and recipes on the community exchange.
Programmatic access to the AI assistant conversation history.
GPU training-run queue: task registry, submit (Idempotency-Key → 409) and status.
Event subscriptions so your infrastructure hears about job completion.
Plans, subscription checkout (Idempotency-Key → 409) and the customer portal. The payment webhook is server-side only.
Operators-only endpoints, audit logs and dependency health probes.
Dive into the reference
The Swagger UI at /api-docs includes every documented endpoint, its schemas and error codes — with request examples you can adapt to any language. The Python SDK page adds quickstarts over the same surface.