BrenzuriStart free
Developer documentation
Start here

Developer documentation

Three ways in, one set of guarantees. Pick the path that matches what you are building.

On this page

Three ways in#

Deliver to your site

Approved articles arrive on your own site as drafts: WordPress through an application password, a hand-built site through a signed webhook. Brenzuri never publishes for you. A hand-built site follows the receiving contract.

  1. Connect the site under Connections.
  2. A person approves an article in Brenzuri.
  3. It appears on your site as a draft.
Deliver to WordPress

Automate with the REST API

Create a key bound to one site, ask for an article, follow the job, read the claims and sources, and hand the result to a person to approve.

  1. Create a key in Developer › API keys.
  2. POST a brief, then POST an article.
  3. Follow the job and read the article.
Start the REST quickstart

Connect an agent over MCP

Claude Code, Cursor or any MCP client signs in over OAuth, picks one site and a daily credit cap, and gets eight tools. None of them approves.

  1. Add the server address to the client.
  2. Sign in and pick a site on the consent page.
  3. Ask for a brief, then an article.
Connect an agent

What Brenzuri guarantees#

These hold in the data layer, not only in the interface. The API cannot be used to get around them.

  • Every claim points at its sources. An article returns its claims, each with the sourceIds that carry it and how many independent origins stand behind it. See Corroboration and flags.
  • Single-source claims are underlined, not deleted. A claim confirmed by fewer than two independent outlets keeps its place in the text with a state other than corroborated. You decide what to do with it.
  • A person approves. No key, token, agent or staff account can. The approve route is not on the list a key may call. See Approval and the AI label.
  • The label is derived. label.reviewedByHuman is read from the approval record of that exact version. Nothing sets it.
  • Delivery is a draft. No connection publishes: WordPress receives the article with status draft, and a custom site receives draft or awaiting_approval, never publish. A key or an agent can only produce a draft. A rewrite of an approved article updates the same WordPress post and sets it back to draft.
  • Every agent action is a version that names the agent, and a failed job releases the credits it held. See Versions and actors and Credits.

Where things live#

There is one host. The REST API cannot be moved to a separate hostname.
SurfaceAddressCredentialGuide
REST APIhttps://{your Brenzuri host}/api/v1API key, bz_live_…Automate, Endpoints
MCP serverhttps://{your Brenzuri host}/mcp/v1OAuth, or agent token bz_mcp_live_…Connect an agent
OAuth metadata/.well-known/oauth-authorization-serverNoneAuthentication
Developer webhooksYour https endpointA signing secret, whsec_…Developer webhooks

The host is the one you sign in at. These pages write it as https://{your Brenzuri host} because it depends on where Brenzuri is deployed.

How the examples are written#

Every example reads two environment variables, so you can paste it and run it.

Shell
export BRENZURI_URL="https://your-brenzuri-host"
export BRENZURI_KEY="bz_live_…"
  • Field names are camelCase. A field that is not set is left out of the JSON; it is never null.
  • The API answers 200 for a created object, not 201, and 204 where nothing comes back.
  • Article, claim, source, brief and job ids are upper-case UUIDs; site, brand and illustration ids are lower-case. Compare them case-insensitively.
  • Failures use one envelope, described under Errors.

Two things to try offline#

Neither calls Brenzuri. The REST API sends no CORS headers, so a browser page on another origin cannot call it, and these tools do not try.

Signature checker

Paste a secret, the X-Brenzuri-Timestamp header, the raw request body and the X-Brenzuri-Signature header. The HMAC-SHA256 is computed in this browser with WebCrypto. Nothing leaves this page: there is no request, no logging and no storage.

Fill in the secret, the timestamp and the body.

Payload explorer

The exact body a developer webhook receives, with keys in the order the engine writes them (sorted). Hover or focus a field to read what it means. Long strings are shortened on screen. The values are made up; the shape is checked against the engine data types.

POSTX-Brenzuri-Event: job.done
  1. {
  2. },
  3. }

Hover or focus a field to see what it is.

What is not here#