🌐 1. Ecosystem Architecture & Multi-Tenancy
The Grapphen Cloud OS operates as a high-throughput, multi-tenant enterprise system. Four core services work together via standardized REST, Webhook, and Real-Time WebSocket channels:
🔐 2. Authentication & Multi-Tenancy
Grapphen uses standard HTTP Bearer authentication via cryptographic API Tokens. All API requests must be transmitted over HTTPS.
| Header | Value | Description |
|---|---|---|
| Authorization | Bearer <YOUR_API_TOKEN> |
Required. Master or Tenant-specific Sanctum API key. |
| X-Tenant-ID | tenant_org_9283fa |
Required for multi-tenant accounts to scope data isolation. |
| X-Grapphen-Secret | <ECOSYSTEM_SSO_SECRET> |
Required for inter-service SSO handshakes between Vox, Rooms, and Mail. |
🎯 3. Grapphen ATS API Reference
Manage talent acquisition, parse unstructured resumes and job descriptions using enterprise Gemini AI, and dispatch submissions.
{
"title": "Senior Cloud Systems Architect",
"description": "Looking for an AWS expert with 7+ years of Kubernetes, Terraform, and SOC-2 compliance...",
"department": "Infrastructure"
}
🎙️ 4. Grapphen Vox Telephony & Voice AI API
Interact with Sofia Voice AI, issue WebRTC softphone tokens, send 10DLC carrier-registered SMS, and access AI call summaries.
{
"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.e30.t-78abx92...",
"identity": "agent_alex_ext_104",
"expires_in": 2700
}
📹 5. Grapphen Rooms WebRTC & Code Sandbox API
Provision live technical interview sessions with synchronized Monaco code editors, real-time audio/video SFU mesh, and proctoring telemetry.
✉️ 6. Grapphen Mail High-Deliverability MTA API
Manage sending domains, automatically verify DNS records (SPF, 2048-bit DKIM, DMARC, BIMI, MTA-STS), and dispatch transactional & campaign emails.
⚡ 7. Webhooks & HMAC Signature Verification
Subscribe to asynchronous events across the Grapphen ecosystem. Every webhook delivery includes an X-Grapphen-Signature header generated using HMAC-SHA256.
// Node.js Example
const crypto = require('crypto');
function verifyWebhook(rawPayload, headerSignature, webhookSecret) {
const expectedSignature = crypto
.createHmac('sha256', webhookSecret)
.update(rawPayload)
.digest('hex');
return crypto.timingSafeEqual(
Buffer.from(headerSignature),
Buffer.from(expectedSignature)
);
}
ats.candidate.created— Dispatched when a candidate profile is ingestedats.application.status_changed— Fired when an applicant moves through hiring stagesvox.call.completed— Dispatched with duration, recording URL, and AI transcriptionvox.sms.received— Inbound SMS received on a tracked phone numberrooms.meeting.ended— Interview concluded; includes code execution summary and reportmail.message.delivered/mail.message.bounced— Mail delivery receipts
💻 8. Code Samples & SDK Quickstart
Send an API request using your preferred language:
curl -X POST "https://api.grapphen.com/v1/ecosystem/ats/check-sender" \
-H "Authorization: Bearer YOUR_API_TOKEN" \
-H "X-Tenant-ID: your-org-slug" \
-H "Content-Type: application/json" \
-d '{"email": "[email protected]"}'
⚠️ 9. Rate Limits & HTTP Status Codes
All API endpoints employ token bucket rate limiting to ensure 99.99% service availability.
| Endpoint Type | Default Quota | Burst Limit |
|---|---|---|
| Standard REST CRUD (ATS, Mail, Vox) | 120 requests / min | 200 requests / min |
| AI Parsers (Resume & JD Extraction) | 30 requests / min | 50 requests / min |
| WebRTC Softphone Token Issuance | 60 requests / min | 100 requests / min |