| Health | /healthz, /readyz, /version, top-level /metrics | Liveness, readiness, build, and Prometheus metrics. |
| Authentication | /auth/signin, /auth/signup, /auth/tokens, /auth/sso/* | Sessions, API tokens, OIDC, and SAML. |
| Home & onboarding | /home/overview, /onboarding/sample-data, /instance | Workspace activation, first-data bootstrap, and public instance discovery. |
| IAM | /iam/permissions, /iam/capabilities, /iam/role-bindings, /roles, /users, /teams, /orgs | Capability catalog, identities, memberships, and workspace selection. |
| Preferences & settings | /workspace/preferences, /settings/*, /billing/* | Personal preferences, workspace defaults, runtime policy, and supported billing configuration. |
| Intake | /intake/{type}/{stream}, /logs, /metrics, /traces, compatibility receivers | Native JSON, OTLP HTTP, and protocol-compatible intake. |
| Query | /query, /query/stream, /query/jobs, /query/running | SQL, PromQL, streaming, async jobs, and cancellation. |
| APM | /apm/overview, /apm/services, /apm/transactions, /apm/dependencies, /apm/errors | Trace-derived service RED metrics, transactions, dependencies, errors, deployments, and projection health. |
| Exploration metadata | /metrics/catalog, /log_patterns, /annotations | Metric discovery, reusable log patterns, and time-bound annotations. |
| Streams | /streams, /streams/{id}, /streams/{id}/settings | Stream lifecycle and runtime settings. |
| Dashboards | /dashboards, /folders, /dashboards/variables/resolve | Dashboards, folders, and variables. |
| Alerting | /alerts/rules, /alerts/incidents, /schedules, /alerts/mutes, /notify/connectors, /notify/policies, /notify/deliveries | Detection, response, on-call, and notifications. |
| Data processing | /functions, /scheduled_pipelines, /connectors, /extend_tables | Transforms, pipelines, sinks, and enrichment. |
| Reports | /scheduled_reports, /report_templates | Report content, schedules, preview, and delivery history. |
| Files & artifacts | /files/download, /files/stream/{token} | Scoped download-token creation and streamed artifact delivery. |
| RUM | /rum/*, /rum/sessions/*, /debug-artifacts | Browser and mobile telemetry, replay, errors, related traces, source maps, and native symbols. |
| Profiles | /profiles, /profiles/intake, /profiles/flamegraph, /profiles/diff | Profile intake, download, flame graphs, and comparisons. |
| Web correlation | /web/search, /web/topology, /web/trace/*, /web/correlation/* | Product search and cross-signal views. |
| Sharing | /resource_shares, /public/share/*, top-level /s/{token} | Authenticated, cross-org, and restricted public shares. |
| Security & governance | /audit, /cipher_keys, /regex_patterns, /auth/jwt/*, /domains | Audit search, encryption, reusable patterns, signing-key rotation, and managed domains. |
| Cluster operations | /clusters, /clusters/{id}/org_map, /node/drain | Remote clusters, organization mapping, node visibility, and graceful drain. |
| Agent | /agent/chat, /agent/investigations, /agent/automations, /agent/approvals, /agent/settings/* | Mole Agent, evidence, workflow, provider, prompt, tool, and MCP control. |
| Commercial control | /marketplace/*, /model_prices | Marketplace, trial or billing integration, and model-cost catalog. |
| Platform system | /system/platform-admins, /system/telemetry, /system/license, /system/audit | Protected _sys administration. |