These endpoints are intentionally unauthenticated so third-party agents can report problems.
They live under
/api/v1/ on the API host and are separate from the API-key-protected sandbox API
under /api/.Discovery
Agents find the feedback surface at the well-known path:GET /api/v1/policy returns the full policy including limits
(max 10 evidence items, 64 KiB per item, titles up to 256 characters, summaries up to 4,096) and
the rate limit (100 submissions per hour per client).
Submit feedback
POST /api/v1/feedback
Responses:
201
"status": "duplicate" and duplicate_of pointing at the
canonical feedback_id. Validation problems return 400 with
{ "error": "validation_failed", "errors": [{ "field", "error", "message" }] }.
More evidence can be attached later with POST /api/v1/feedback/{id}/attachments, and any report
can be read back with GET /api/v1/feedback/{id}.
Submit an observation
POST /api/v1/observations is the lightweight form for low-confidence or repetitive signals —
only surface, domain, agent_vendor, and agent_product are required:
Receipts
GET /api/v1/receipts/{id} returns the current state of a submission. status is one of
accepted, duplicate, rejected, queued, or needs_more_evidence; once a report is triaged,
feedback_status (open, accepted, resolved, wontfix, spam), quality_score, and
duplicate_of are filled in so an agent can learn whether its report was useful.
Issue tracking
Each new (non-duplicate) report is filed as an issue in OpenComputer’s issue tracker, with severity mapped to issue priority and the evidence included.GET /api/v1/feedback/{id} exposes
the resulting link as tracker: { "provider": "linear", "id": "ENG-123", "url": "..." } (or
null while none exists). Duplicate submissions don’t open new issues; they add an observation to
the original report.
Signing (optional)
Anonymous submissions are accepted. Agents that want a persistent identity — and the reputation that comes with reports being accepted — can sign requests with an Ed25519 key:
Requests carrying a bad or stale signature are rejected with
401.
From the CLI
Theoc CLI ships an emitter so agents running inside OpenComputer (or anywhere oc is
installed) can report issues without hand-writing JSON — see oc feedback. It
works against any feedback.now receiver, not only OpenComputer.