Regnora is the AI workspace next to your quality or document management system. Your system pushes documents for a user, hands that user a link, and they work with the **Assistant** in Regnora. Results stay there, or your system pulls them back as Word or Markdown. There is no chat or analysis API to build against.

This page is the short version for whoever builds the integration. The [API reference](/integrate/api-reference/) lists every endpoint, field and error code.

## The whole flow

```text
Your system                   Regnora API                  User's browser
    │                              │                              │
    │ POST /documents              │                              │
    │ (user, file)                 │                              │
    │─────────────────────────────▶│                              │
    │ 202 { id, "processing" }     │                              │
    │◀─────────────────────────────│                              │
    │                              │                              │
    │ POST /sessions               │                              │
    │ (user, document_ids, prompt) │                              │
    │─────────────────────────────▶│                              │
    │ 202 { session_id, url }      │                              │
    │◀─────────────────────────────│                              │
    │                              │                              │
    │ show url as a button ─ ─ ─ ─ ─ ─ ─ ─ ─ ─ ─ ─ ─ ─ ─ ─ ─ ─ ─ ▶│
    │                              │ open url: signed in,         │
    │                              │ chat opens                   │
    │                              │◀─────────────────────────────│
    │                              │ Assistant works on the       │
    │                              │ user's documents             │
    │                              │                              │
    │                              │ user downloads results       │
    │                              │─────────────────────────────▶│
    │                              │                              │
    │ GET /documents/{id}          │                              │
    │ /export.docx   (optional)    │                              │
    │─────────────────────────────▶│                              │
    │ 200  current version         │                              │
    │◀─────────────────────────────│                              │
```

Every user you send in gets a private workspace in Regnora, created on first use. The Assistant in their session sees the documents pushed for them and nothing else, so your access model stays yours: you decide which files a user may push and who gets the button.

## Before you start

- **One organisation, one API key.** Regnora creates your organisation and hands over the first key once. Owners and admins can create more under **Settings → API keys**; the raw key is shown only at creation.
- **Base URL.** Production is `https://api.regnora.com/api/integrations/v1`. You get a test environment and key during onboarding. The OpenAPI document is at `/api/integrations/v1/openapi.json` on the same host, with interactive docs at `/docs`, if you prefer to generate a client.
- **Every request** carries the key as `Authorization: Bearer rk_live_…`.

## Step 1: push documents for a user

`user` is the person's email. The document lands in their private workspace. `external_ref` is optional: your own identifier, stored and echoed back.

```bash
curl -X POST "$BASE/documents" \
  -H "Authorization: Bearer $KEY" \
  -F "user=jane@example.com" \
  -F "file=@procedure.docx" \
  -F "external_ref=QMS-DOC-1234"
```

```json
{ "id": "…", "status": "processing", "external_ref": "QMS-DOC-1234", "version": 1 }
```

Processing takes seconds to a few minutes. `GET /documents/{id}` reports the status; you do not have to wait for `ready` before opening a session. When the file changes on your side, `POST /documents/{id}/versions` with the new file keeps the same `id` and moves `version` once processed. Pushing bytes Regnora already has answers `200` with the existing document, so retries are safe.

Supported: Word, PDF, Excel, CSV, Markdown and plain text, up to 50 MB. Omit `user` and the document goes into the organisation's shared default project instead.

## Step 2: open a session and send the user in

Attach documents from the user's workspace by id, or push new ones in the same call with `files`. With a `prompt`, the Assistant starts before the user arrives; without one, the chat waits for them.

```bash
curl -X POST "$BASE/sessions" \
  -H "Authorization: Bearer $KEY" \
  -F "user=jane@example.com" \
  -F "document_ids=$ID" \
  -F "prompt=Review this procedure against ISO 13485 clause 4.2.4."
```

```json
{
  "session_id": "…",
  "status": "processing",
  "url": "https://app.regnora.com/auth/verify?token=…",
  "documents": [{ "id": "…", "status": "ready", "external_ref": "QMS-DOC-1234", "version": 1 }]
}
```

Put `url` behind a button in your product. Opening it signs the user in without a password and lands them in the chat.

The link is a credential; see [Security model](#security-model) for its lifetime. Need a fresh one, for instance when the user comes back the next day? Every `GET /sessions/{id}` mints a new link, and `GET /sessions?user=` lists a user's sessions, each with one.

## Step 3: get results back

Whatever the user produces in Regnora, they download from the app: a revised procedure as Word, a gap-analysis report as Excel, a drafted document as Word or Markdown. If a file belongs in your system, they upload it there like any other document.

To automate that round trip for documents, the API serves the current version of any document pushed under your key, whether it was revised in Regnora or not:

```bash
curl "$BASE/documents/$ID/export.docx" -H "Authorization: Bearer $KEY" -o procedure.docx
```

`export.md` returns Markdown. A `409 document_processing` means nothing is ready to export yet; poll the status and retry. Need other results over the API? [Get in touch](/resources/support/).

## Security model

- **Your organisation is your tenant.** Nothing crosses organisations. The API key acts as the whole organisation: it can push, read the status of and export any document pushed under it, and open sessions for any of your users.
- **Each user has a private workspace.** Documents and chats in it are visible to that user alone, not to other users you send in. The Assistant in their session reaches those documents and nothing else. Every document pushed for a user is attributed to them.
- **API keys.** HTTPS only, as a bearer token. Keys are stored hashed and shown once, at creation. Owners and admins revoke them in **Settings → API keys**, effective on the next request. Each use records a last-used time.
- **Login links.** A link signs the user in without a password and opens a 24-hour app session. The link itself is valid for 20 minutes and can be used more than once in that window, so show it only to that user, over a channel you trust. Regnora sends your users no email.
- **Regular accounts.** The account behind a workspace is a normal Regnora account tied to that email. The user can also sign in themselves at [app.regnora.com](https://app.regnora.com) by email link, or with a Google or Microsoft account on that address.
- **Terms.** By opening a session or pushing for a user you confirm they have accepted Regnora's [terms](https://regnora.com/terms) and [privacy policy](https://regnora.com/privacy).
- **Data stays in the EU.** See [Data residency & security](/reference/data-residency-and-security/) for processing, AI usage and audit trail.

## Conventions

- **Versioned path.** `v1` does not break; additions are announced in advance. Treat any `status` you do not recognise as `processing`.
- **Errors are JSON** with a stable `code`, a readable `message` and a `request_id` to quote when you [contact support](/resources/support/). Rate limits answer `429` with `Retry-After`.