User-facing routes are under /api/v1. The version is part of the path, so a future /api/v2 can exist beside it without changing a single call you have already written. Two routes sit outside the prefix because they describe the service rather than an account: /api/health and /api/openapi.json. The MCP endpoint at /mcp is documented on the MCP page.
Requests and responses are JSON, UTF-8, with one exception: an attachment download answers the file's bytes. Timestamps come in two shapes, both UTC: the camelCase fields on credentials (createdAt, lastUsedAt, expiresAt) are ISO 8601 with a trailing Z, while the snake_case fields on a profile, an alias and a domain (created_at, verified_at, created, modified) are YYYY-MM-DD HH:MM:SS.