Command Center
Plans and pricing · Sign in

Command Center API

The health of your Salesforce orgs as data. Read the Org Health Index and grade, every issue with its history, reviews, monitoring, compliance evidence and activity; work issues from your own tools; stop a deployment when an org's health drops; get events by webhook; and let AI assistants use it all through the MCP server.

The API comes with the Professional and Enterprise plans at no extra charge. Version 1.0.0. Base URL:

https://health.dream.cloud/v1

Quick start

  1. In the Command Center, open Admin > API access (owners and admins) and make a token. Copy it: it is shown only once.
  2. Call the API with the token in the Authorization header:
curl -s -H "Authorization: Bearer $DREAM_TOKEN" "https://health.dream.cloud/v1/orgs"

Then the health of one org (the ids come from /orgs):

curl -s -H "Authorization: Bearer $DREAM_TOKEN" "https://health.dream.cloud/v1/health?org=12"
{
  "ok": true,
  "data": {
    "org": {
      "id": 12,
      "name": "Example Co Production"
    },
    "index": 74.6,
    "grade": "C",
    "healthy_at": 80,
    "review": {
      "id": 311,
      "run_id": "RUN-2026-0311",
      "finished_at": "2026-10-01T06:02:11Z"
    },
    "areas": [
      {
        "area": "Security",
        "area_name": "Security",
        "score": 68.2,
        "checks": 14
      },
      {
        "area": "Cost Efficiency",
        "area_name": "Licenses and cost",
        "score": 81.0,
        "checks": 9
      }
    ],
    "projection": {
      "base": 74.6,
      "quick": {
        "n": 6,
        "gain": 9.1,
        "to": 83.7
      }
    }
  },
  "request_id": "req_2c7e4a9f0b1d3e5a6c8b"
}

Tokens and scopes

A token looks like drm_3f9c...: drm_ and 40 hexadecimal characters, the last 8 a checksum, so a mistyped token is refused at once and secret scanners can recognize one. We keep only a fingerprint of it; if a token is lost, replace it.

Each token has scopes. Choose a preset or pick scopes one by one:

PresetScopes
Read onlyorgs:read, health:read, reviews:read, issues:read, monitoring:read, compliance:read, activity:read
Ticketing integrationorgs:read, issues:read, issues:items, issues:write, webhooks:manage
Deploy pipelineorgs:read, health:read, reviews:read, monitoring:read, monitoring:write
Full accessorgs:read, orgs:write, health:read, reviews:read, reviews:run, issues:read, issues:items, issues:write, monitoring:read, monitoring:write, compliance:read, activity:read, webhooks:manage
ScopeAllows
orgs:readSee the connected orgs, their connection and planning answers
orgs:writeUpdate an org's planning answers
health:readOrg Health Index, grade, areas, projection, deploy gate, savings and the saved plan
reviews:readReviews, their scores and the 62 checks
reviews:runStart an Org Health Review
issues:readThe issue log (findings and alerts), history and accepted exceptions
issues:itemsThe affected items of a check or issue (they can include user names)
issues:writeAcknowledge, assign, snooze, dismiss, resolve, comment, link tickets, accept exceptions
monitoring:readMonitors, alerts and the Security Health Check
monitoring:writeOpen and close deploy windows, re-check a monitor
compliance:readSOC 2, HIPAA, ISO 27001, Ontario PHIPA, PIPEDA, GDPR, UK GDPR and Quebec Law 25 evidence and access reviews
activity:readThe activity log (who did what)
webhooks:manageCreate and manage webhook endpoints and see deliveries

Answers and errors

Every answer is JSON (UTF-8). A success has "ok": true and the result in data; an error has "ok": false and an error with a code, the HTTP status it stands for and a message you can show. Every answer carries a request_id; send it to us if something looks wrong.

HTTP status codes. The HTTP status of every answer is the error.status of its body: 200 for a success, and 401, 403, 404, 409, 422, 429 or 500 for an error, as in the table below. The body is the same JSON either way, so reading ok keeps working. Every answer carries an X-Request-Id header with its request_id, and a rate_limited answer carries Retry-After in seconds. MCP answers use HTTP 200 as JSON-RPC expects, except 401, 403 and 429 when the token check refuses the call. If a proxy or the network answers 502, 503 or 504, wait a few seconds and try again.
{
  "ok": false,
  "error": {
    "code": "insufficient_scope",
    "status": 403,
    "message": "This token does not have the issues:write scope."
  },
  "request_id": "req_0f2d4b6a8c1e3a5c7e9b"
}
error.codestatusWhen
unauthorized401No token, an unknown, revoked or expired token, or a replaced token after its 24 hours
plan_required403The account is not on Professional or Enterprise
ip_not_allowed403The token only accepts calls from its allowed IP addresses
insufficient_scope403The token lacks the scope the operation needs
not_found404Unknown operation, org, review, issue, endpoint or delivery
conflict409The request clashes with the current state, for example a review or a deploy window is already running
invalid422A parameter is missing or not valid; the message says which
limit_reached429A review limit of the plan: one review on demand per org every 24 hours, the org's monthly limit or the account's daily limit; retry_after gives the seconds until the next review can start
rate_limited429Too many calls for this token this minute or today; retry_after gives the seconds to wait
internal500Something failed on our side; retry, and send us the request_id if it keeps happening

Send parameters of a GET in the query string. Send a POST as JSON (Content-Type: application/json) with an action and its fields; org may go in the query string or the body. Times are ISO 8601 in UTC. Issue ids look like FND-12 (a finding of a review) or ALR-7 (a monitoring alert); orgs, reviews, endpoints and deliveries have numeric ids.

Limits and paging

PlanTokensWebhook endpointsCalls a minute, per tokenCalls a day, per tokenReviews on demand, per org every 24 hoursReviews on demand, per org a monthReviews on demand, across the account a day
Professional1056010,00012010
Enterprise2520300100,00016025

Over a limit, the answer is rate_limited with retry_after in seconds. Reviews started with POST reviews share their limits with the Run review button: over one of them the answer is limit_reached, also with retry_after, and while a review of that org is running it is conflict. The review that runs by itself each month never counts, and Enterprise limits can be set in your agreement. Lists return up to limit items (1 to 200, 50 by default) and a next_cursor; pass it as cursor to get the next page. It is null on the last page.

Reference

Every operation, its scope and its parameters. The OpenAPI file has the full response schemas.

Your token

GET /v1/me any valid token

The calling token: its scopes, orgs, expiry and your plan's limits.

Orgs

GET /v1/orgs scope orgs:read

Connected orgs with their connection, monitoring and latest review; with id, one org and its planning answers.

ParameterTypeInDescription
idintegerqueryOne org
POST /v1/orgs · action planning scope orgs:write

Update an org's five planning answers.

ParameterTypeInDescription
org requiredintegerbodyOrg id
renewal_monthintegerbodyMonth (1 to 12) the Salesforce contract renews
retention_notesstringbodyData you must keep, and for how long
release_cadencestringbodyHow often you release
known_exceptionsstringbodyWhat is intentional and should stay
prioritystringbodyWhat matters most

Org Health

GET /v1/health scope health:read

Latest Org Health Index, grade and areas, the trend, what the quick fixes and your decisions would reach, and the saved plan.

ParameterTypeInDescription
org requiredintegerqueryOrg id (from GET /v1/orgs) (e.g. 12)

Deploy gate

GET /v1/gate scope health:read

Pass or fail against your thresholds, with the reasons: for deploy pipelines.

ParameterTypeInDescription
org requiredintegerqueryOrg id (from GET /v1/orgs) (e.g. 12)
min_gradestringqueryLowest acceptable grade (e.g. C)
min_indexnumberqueryLowest acceptable Org Health Index (0 to 100) (e.g. 70)
max_criticalintegerqueryMost open critical issues allowed (e.g. 0)
max_new_criticalintegerqueryMost critical issues opened by the latest review or in the last 24 hours (e.g. 0)
max_dropnumberqueryLargest allowed fall of the Index since the previous review (e.g. 5)

Reviews

GET /v1/reviews scope reviews:read

Reviews, newest first; with id, one review with its area scores and links.

ParameterTypeInDescription
orgintegerqueryOnly this org (from GET /v1/orgs) (e.g. 12)
idintegerqueryOne review
cursorstringquerynext_cursor from the previous page
limitintegerqueryItems per page, 1 to 200 (default 50) (e.g. 50)
POST /v1/reviews · action start scope reviews:run

Start an Org Health Review; it runs in the background (poll GET /v1/reviews?org=).

ParameterTypeInDescription
org requiredintegerbodyOrg id

Checks of a review

GET /v1/checks scope reviews:read

The checks of a review with value, status, score, weight and how it gets fixed.

ParameterTypeInDescription
review requiredintegerqueryReview id
statusstringqueryOnly this status
include_itemsbooleanqueryAdd the affected items (needs issues:items)

Review documents

GET /v1/documents scope reviews:read

A finished review's Executive Brief or Full Review: as text in the answer (the Full Review includes its commentary), or as a PDF download link that works for 15 minutes.

ParameterTypeInDescription
review requiredintegerqueryReview id (from GET /v1/reviews) (e.g. 165)
typestringqueryWhich document (default brief)
formatstringquerytext (default) or pdf

Issues

GET /v1/issues scope issues:read

Findings (FND-) and alerts (ALR-); with id, one issue with its history, exceptions and how to fix it.

ParameterTypeInDescription
orgintegerqueryOnly this org (from GET /v1/orgs) (e.g. 12)
idstringqueryOne issue, for example FND-41
statusstringqueryopen (default: open, acknowledged, snoozed), acknowledged, snoozed, dismissed, resolved or all
severitystringquerywarn or critical
kindstringqueryfinding or alert
updated_sincestringqueryOnly issues changed at or after this ISO time
include_itemsbooleanqueryAdd the affected items (needs issues:items)
cursorstringquerynext_cursor from the previous page
limitintegerqueryItems per page, 1 to 200 (default 50) (e.g. 50)
POST /v1/issues · action acknowledge scope issues:write

Acknowledge an issue, optionally naming the owner.

ParameterTypeInDescription
id requiredstringbodyIssue id, e.g. FND-41
ownerstringbodyEmail of a user of your account
POST /v1/issues · action assign scope issues:write

Change the owner.

ParameterTypeInDescription
id requiredstringbodyIssue id
owner requiredstringbodyEmail of a user of your account
POST /v1/issues · action snooze scope issues:write

Snooze until a date.

ParameterTypeInDescription
id requiredstringbodyIssue id
until requiredstringbodyYYYY-MM-DD
POST /v1/issues · action dismiss scope issues:write

Dismiss with a reason.

ParameterTypeInDescription
id requiredstringbodyIssue id
reason requiredstringbodyWhy
note requiredstringbodyDetails
POST /v1/issues · action resolve scope issues:write

Report it fixed; the next check or review confirms the fix, or reopens the issue.

ParameterTypeInDescription
id requiredstringbodyIssue id
notestringbodyWhat was done
POST /v1/issues · action reopen scope issues:write

Reopen.

ParameterTypeInDescription
id requiredstringbodyIssue id
POST /v1/issues · action comment scope issues:write

Add a note to the history.

ParameterTypeInDescription
id requiredstringbodyIssue id
note requiredstringbodyThe note
POST /v1/issues · action link scope issues:write

Link a ticket of your own system (Jira, ServiceNow, Azure DevOps, ...).

ParameterTypeInDescription
id requiredstringbodyIssue id
ticket_ref requiredstringbodyTicket key, e.g. OPS-7
ticket_urlstringbodyhttps link to the ticket
POST /v1/issues · action help scope issues:write

Ask for help on it.

ParameterTypeInDescription
id requiredstringbodyIssue id
notestringbodyWhat you need
POST /v1/issues · action recheck scope issues:write

Re-run the monitor behind an alert now.

ParameterTypeInDescription
id requiredstringbodyAlert id, e.g. ALR-12
POST /v1/issues · action exception scope issues:write

Accept an exception for one affected item, with a reason and a review date.

ParameterTypeInDescription
id requiredstringbodyIssue id
item requiredstringbodyThe item's key (from include_items)
reason requiredstringbodyWhy it stays
ownerstringbodyWho reviews it
review_monthsintegerbody3, 6, 12 (default) or 24

Monitoring

GET /v1/monitors scope monitoring:read

The org's monitors with their latest result.

ParameterTypeInDescription
org requiredintegerqueryOrg id (from GET /v1/orgs) (e.g. 12)
POST /v1/monitors · action recheck scope monitoring:write

Re-run one monitor now.

ParameterTypeInDescription
org requiredintegerbodyOrg id
key requiredstringbodyMonitor key

Security Health Check

GET /v1/healthcheck scope monitoring:read

Salesforce Security Health Check score history and the settings at risk.

ParameterTypeInDescription
org requiredintegerqueryOrg id (from GET /v1/orgs) (e.g. 12)

Deploy windows

GET /v1/windows scope monitoring:read

Deploy windows of an org.

ParameterTypeInDescription
org requiredintegerqueryOrg id (from GET /v1/orgs) (e.g. 12)
POST /v1/windows · action open scope monitoring:write

Open a deploy window: configuration changes during it are expected, not alerts.

ParameterTypeInDescription
org requiredintegerbodyOrg id
minutesintegerbodyLength, 5 to 480 (default 60)
referencestringbodyYour deploy or release reference
POST /v1/windows · action close scope monitoring:write

Close it: the monitors re-check and a summary of the changes is sent to your webhooks.

ParameterTypeInDescription
org requiredintegerbodyOrg id
windowintegerbodyWindow id (default: the open one)

Compliance

GET /v1/compliance scope compliance:read

Control status and evidence for SOC 2, HIPAA, ISO 27001, Ontario PHIPA, PIPEDA, GDPR, UK GDPR or Quebec Law 25.

ParameterTypeInDescription
org requiredintegerqueryOrg id (from GET /v1/orgs) (e.g. 12)
frameworkstringqueryFramework (default: the first that fits the org, from its own answers or your organization's) (e.g. soc2)

Evidence exports

GET /v1/evidence scope compliance:read

A signed-off evidence export with its SHA-256, which anyone holding it can verify.

ParameterTypeInDescription
org requiredintegerqueryOrg id (from GET /v1/orgs) (e.g. 12)
frameworkstringqueryFramework (default: the first that fits the org, from its own answers or your organization's)

Verify an export

GET /v1/verify no token

Check that an evidence export came from the Command Center (no token needed).

ParameterTypeInDescription
hash requiredstringquerySHA-256 of the export

Access reviews

GET /v1/access_reviews scope compliance:read

Access reviews of admin-level access, their decisions and sign-off.

ParameterTypeInDescription
org requiredintegerqueryOrg id (from GET /v1/orgs) (e.g. 12)

Savings and capacity

GET /v1/savings scope health:read

Licenses you could reclaim and when storage fills up.

ParameterTypeInDescription
org requiredintegerqueryOrg id (from GET /v1/orgs) (e.g. 12)

Improvement plan

GET /v1/plan scope health:read

The saved improvement plan: each item, its issue and status, projected against achieved.

ParameterTypeInDescription
org requiredintegerqueryOrg id (from GET /v1/orgs) (e.g. 12)

Accepted exceptions

GET /v1/exceptions scope issues:read

Accepted exceptions with their owner, reason and review date.

ParameterTypeInDescription
orgintegerqueryOnly this org (from GET /v1/orgs) (e.g. 12)

Activity

GET /v1/activity scope activity:read

Who did what, newest first.

ParameterTypeInDescription
sincestringqueryOnly entries at or after this ISO time
cursorstringquerynext_cursor from the previous page
limitintegerqueryItems per page, 1 to 200 (default 50) (e.g. 50)

Webhooks

GET /v1/webhooks scope webhooks:manage

Your webhook endpoints.

POST /v1/webhooks · action create scope webhooks:manage

Add an endpoint; the signing secret is returned once.

ParameterTypeInDescription
url requiredstringbodyhttps URL
eventsstringbodyComma-separated events, or all
descriptionstringbodyWhat it is for
POST /v1/webhooks · action delete scope webhooks:manage

Remove an endpoint.

ParameterTypeInDescription
endpoint requiredintegerbodyEndpoint id
POST /v1/webhooks · action rotate scope webhooks:manage

New signing secret (returned once).

ParameterTypeInDescription
endpoint requiredintegerbodyEndpoint id
POST /v1/webhooks · action test scope webhooks:manage

Send a webhook.test event.

ParameterTypeInDescription
endpoint requiredintegerbodyEndpoint id
POST /v1/webhooks · action redeliver scope webhooks:manage

Send one delivery again.

ParameterTypeInDescription
delivery requiredintegerbodyDelivery id
POST /v1/webhooks · action enable scope webhooks:manage

Turn an endpoint on or off.

ParameterTypeInDescription
endpoint requiredintegerbodyEndpoint id
enabled requiredbooleanbodytrue or false

Webhook deliveries

GET /v1/deliveries scope webhooks:manage

Deliveries, newest first, with status and attempts.

ParameterTypeInDescription
endpointintegerqueryOnly this endpoint
statusstringquerypending, retrying, delivered or failed
cursorstringquerynext_cursor from the previous page
limitintegerqueryItems per page, 1 to 200 (default 50) (e.g. 50)

Webhooks

Add an endpoint on the API access page or with POST /v1/webhooks (action create). The URL must use https and a public host name. You get the endpoint's signing secret once; a new one replaces it at once (rotate).

We POST each event as JSON with these headers: Dream-Event (the type), Dream-Event-Id, Dream-Delivery, Dream-Timestamp and Dream-Signature: t=<unix time>,v1=<hex>, where v1 is the HMAC-SHA256 of <t>.<body> with the endpoint's secret. Check it on the exact bytes you received, and refuse a timestamp older than five minutes.

import hashlib, hmac, time

def dream_signature_ok(secret: str, header: str, body: bytes, tolerance: int = 300) -> bool:
    parts = dict(p.split("=", 1) for p in header.split(",") if "=" in p)
    t, v1 = parts.get("t", ""), parts.get("v1", "")
    if not t.isdigit() or abs(time.time() - int(t)) > tolerance:
        return False
    want = hmac.new(secret.encode(), t.encode() + b"." + body, hashlib.sha256).hexdigest()
    return hmac.compare_digest(want, v1)
const crypto = require("crypto");

function dreamSignatureOk(secret, header, rawBody, tolerance = 300) {
  const parts = Object.fromEntries(header.split(",").map((p) => p.split("=", 2)));
  const t = parts.t || "", v1 = parts.v1 || "";
  if (!/^\d+$/.test(t) || Math.abs(Date.now() / 1000 - Number(t)) > tolerance) return false;
  const want = crypto.createHmac("sha256", secret).update(t + "." + rawBody).digest("hex");
  return want.length === v1.length && crypto.timingSafeEqual(Buffer.from(want), Buffer.from(v1));
}

Answer with any 2xx within 10 seconds. Otherwise we try again after 1, 5, 30, 120, 360 and 720 minutes, then daily, for 3 days; after that the delivery is marked failed. You can send any delivery again from the API access page or with redeliver. A delivery can arrive twice or out of order: use Dream-Event-Id to skip one you have seen.

{
  "id": "evt_6b1f0c9e2d4a8b3f7e5c1a0d",
  "type": "issue.opened",
  "created_at": "2026-10-02T09:14:05Z",
  "api_version": "v1",
  "account": {
    "id": 42,
    "name": "Example Co"
  },
  "data": {
    "issue": {
      "id": "ALR-318",
      "kind": "alert",
      "org": 12,
      "title": "Users with Modify All Data",
      "check": "sec.modify_all_users",
      "area": "Security",
      "area_name": "Security",
      "severity": "critical",
      "status": "open",
      "value_text": "9 users have Modify All Data",
      "opened_at": "2026-10-02T09:14:02Z",
      "resolved_at": null,
      "resolved_by": null,
      "due_at": "2026-10-05T09:14:02Z",
      "owner": null,
      "ticket": null,
      "verify_state": null,
      "link": "https://health.dream.cloud/app/issue.html?id=ALR-318"
    },
    "org": {
      "id": 12,
      "name": "Example Co Production"
    },
    "note": null
  }
}
EventWhen
review.completedA review finished and was scored
health.grade_changedA review gave a different grade than the previous review
health.index_droppedThe Org Health Index fell by 5 points or more since the previous review
issue.openedA review or a monitor opened a finding or an alert
issue.updatedSomeone acknowledged, assigned, snoozed, dismissed, commented on or linked an issue
issue.resolvedAn issue was resolved (by a check, a review, a person, Jira or the API)
issue.reopenedA resolved issue came back, or a fix was not confirmed by the next check
issue.overdueAn open issue passed its due date
issue.fix_confirmedThe next check or review confirmed a fix that a person or ticket reported
plan.item_doneAn item of the saved improvement plan was fixed
exception.expiringAn accepted exception reaches its review date within 14 days
exception.expiredAn accepted exception passed its review date and counts again
connection.expiredSalesforce refused the stored connection; the org needs to be reconnected
deploy_window.closedA deploy window closed; the changes it covered are summarized
token.expiringAn API token expires within 14 days
token.leakedGitHub found an API token in a public place; it was revoked at once
webhook.testA test event sent from the API access page or the API

MCP server

AI assistants that speak the Model Context Protocol can use the Command Center through its MCP server: streamable HTTP with JSON answers, protocol versions 2025-06-18, 2025-03-26 and 2024-11-05. Send the API token as a header; the assistant sees only the tools the token's scopes allow.

https://health.dream.cloud/v1/mcp

Claude Code

claude mcp add --transport http dream https://health.dream.cloud/v1/mcp --header "Authorization: Bearer drm_your_token"

Cursor (~/.cursor/mcp.json)

{
  "mcpServers": {
    "dream": {
      "url": "https://health.dream.cloud/v1/mcp",
      "headers": {
        "Authorization": "Bearer drm_your_token"
      }
    }
  }
}

VS Code (.vscode/mcp.json; VS Code asks for the token once and stores it)

{
  "inputs": [
    {
      "type": "promptString",
      "id": "dream-token",
      "description": "Dream API token",
      "password": true
    }
  ],
  "servers": {
    "dream": {
      "type": "http",
      "url": "https://health.dream.cloud/v1/mcp",
      "headers": {
        "Authorization": "Bearer ${input:dream-token}"
      }
    }
  }
}

Custom connectors in Claude.ai and ChatGPT sign in with OAuth, which the Command Center does not offer yet; use an assistant that can send a header, such as the ones above.

ToolWhat it does
list_orgsList the connected Salesforce orgs with their latest Org Health Index and grade.
get_org_healthOrg Health Index, grade, the five areas, the trend and what the quick fixes and decisions would reach.
check_deploy_gateCheck an org against deploy thresholds (grade, index, critical issues, drop) and say why it passes or fails.
list_reviewsList Org Health Reviews, newest first.
list_review_checksThe checks of one review with value, status and score.
get_review_documentA finished review's Executive Brief (type brief, the default) or Full Review (type full) as plain text, including its written commentary. Find the review id with list_reviews.
list_issuesList open findings and alerts (or another status), newest first.
get_issueOne issue with its history, accepted exceptions and how to fix it.
list_monitorsThe org's monitors with their latest result.
get_health_checkSalesforce Security Health Check score and settings at risk.
get_complianceSOC 2, HIPAA, ISO 27001, Ontario PHIPA, PIPEDA, GDPR, UK GDPR or Quebec Law 25 control status and evidence.
get_savingsLicenses you could reclaim and when storage fills up.
get_planThe saved improvement plan and its progress.
list_activityWho did what in the Command Center, newest first.
start_reviewStart an Org Health Review of an org (runs in the background).
acknowledge_issueAcknowledge an issue, optionally naming the owner by email.
assign_issueChange an issue's owner (email of a user of the account).
snooze_issueSnooze an issue until a date (YYYY-MM-DD).
comment_on_issueAdd a note to an issue's history.
link_ticketLink a ticket from your own system to an issue.
resolve_issueReport an issue fixed; the next check or review confirms it or reopens it.
open_deploy_windowOpen a deploy window so configuration changes during it are expected.
close_deploy_windowClose the org's open deploy window and re-check.

Recipes

Stop a deployment when an org's health drops

Call /gate before you deploy. It answers pass with the rules you set: min_grade, min_index, max_critical, max_new_critical, max_drop. Open a deploy window around the deployment so the changes it makes count as expected, not as changes outside your release windows; closing it re-checks security and sends deploy_window.closed with a summary.

# GitHub Actions: a step before the deploy (the token is a repository secret)
- name: Check org health
  env:
    DREAM_TOKEN: ${{ secrets.DREAM_TOKEN }}
    DREAM_API: https://health.dream.cloud/v1
  run: |
    curl -s -H "Authorization: Bearer $DREAM_TOKEN" "$DREAM_API/gate?org=12&min_grade=B&max_new_critical=0" > gate.json
    jq -e '.ok and .data.pass' gate.json || { jq '.data.reasons // .error' gate.json; exit 1; }
    curl -s -X POST -H "Authorization: Bearer $DREAM_TOKEN" -H "Content-Type: application/json" \
      -d '{"action": "open", "org": 12, "minutes": 60, "reference": "release ${{ github.sha }}"}' "$DREAM_API/windows"

The same two calls work from Gearset, Copado, Azure Pipelines or any tool that can run a script or an HTTP request. Close the window with {"action": "close", "org": 12} when the deployment ends.

Tickets in Jira, ServiceNow or Azure DevOps

The Command Center already creates Jira Cloud and ServiceNow tickets from the Issues page (Settings). To run your own flow instead: subscribe an endpoint to issue.opened, create the ticket, then link it back with POST /v1/issues action link (ticket_ref, ticket_url). Resolve the issue with action resolve when the ticket closes: the next check confirms the fix (issue.fix_confirmed) or reopens the issue (issue.reopened).

Slack and Microsoft Teams

Alerts can go to Slack and Teams without code (Settings > Notifications). For your own messages, send webhook events through a small relay (for example a serverless function) that checks the signature and posts to your channel.

Power BI, Tableau and spreadsheets

Point a web data source at /health, /reviews or /issues with the header Authorization: Bearer ... and a read-only token. In Power BI: Get data > Web > Advanced, add the header, then expand data.

Splunk and Microsoft Sentinel

Poll /activity?since=... every few minutes for the audit trail (who did what, and when), or relay webhook events to your HTTP event collector.

Compliance tools such as Drata and Vanta

/evidence returns the evidence for SOC 2, HIPAA, ISO 27001, Ontario PHIPA, PIPEDA, GDPR, UK GDPR or Quebec Law 25 (by default the first that fits the org) with its sha256; anyone can check an export with /verify?hash=..., no token needed. Attach the export and the verification link to your control.

Salesforce External Services

Use the API from Salesforce Flow without code. Import openapi-salesforce.json, a subset (orgs, health, gate, issues) written for External Services.

  1. External Credential (Setup > Named Credentials > External Credentials): authentication protocol Custom. Add a principal with an authentication parameter named token holding your API token, and a custom header Authorization with the value {!'Bearer ' & $Credential.Dream_API.token} (use your External Credential's API name).
  2. Named Credential: URL https://health.dream.cloud/v1, the External Credential above, Allow Formulas in HTTP Header on and Generate Authorization Header off.
  3. Give the users or the flow's running user access to the principal in a permission set (External Credential Principal Access).
  4. External Services: add a service from the API specification file, choose the Named Credential and the operations. They then appear as actions in Flow Builder.

Every answer has ok: branch on it in the flow, because errors also come back as success at the HTTP level.

Files

Versions

The version is in the path (/v1). We add fields, operations and events without notice, so ignore what you do not know. Anything that would break a client comes in a new version, announced here in advance.

Version 1.0.0 · Questions: contact us · Terms · Privacy Policy