Content API
The typed REST API humans, scripts and agents all write through.
Authentication
Every write carries a key: authorization: Bearer prelo_…. Keys have roles (viewer, author, editor, admin) and appear in the audit log by name. Published content reads anonymously; drafts and private types need a key.
Endpoints
Drafts & preview
Drafts are visible to author-and-above credentials only — a studio session cookie or an author/editor/admin key. Enforced server-side: anonymous list responses are filtered to published (?status=draft can't leak them), and a draft's detail URL 404s for anonymous callers. In one-process mode the visitor's cookie reaches the site module, so anyone signed into the studio sees drafts on the real site — the studio editor's Preview link opens the item that way. See Embed & one process. Shareable tokenized preview links don't exist yet.
Example
Built for agents
Every site serves /llms.txt — a plain-text map of the content model any agent can read before writing. Errors return {error, hint, problems} with the exact fix, and publishing still respects the key’s role.