Command Center API
The health of your Salesforce orgs as data. Read the Org Health Index and grade, every issue with its history, reviews, monitoring, compliance evidence and activity; work issues from your own tools; stop a deployment when an org's health drops; get events by webhook; and let AI assistants use it all through the MCP server.
The API comes with the Professional and Enterprise plans at no extra charge. Version 1.0.0. Base URL:
https://health.dream.cloud/v1
Quick start
- In the Command Center, open Admin > API access (owners and admins) and make a token. Copy it: it is shown only once.
- Call the API with the token in the
Authorizationheader:
curl -s -H "Authorization: Bearer $DREAM_TOKEN" "https://health.dream.cloud/v1/orgs"
Then the health of one org (the ids come from /orgs):
curl -s -H "Authorization: Bearer $DREAM_TOKEN" "https://health.dream.cloud/v1/health?org=12"{
"ok": true,
"data": {
"org": {
"id": 12,
"name": "Example Co Production"
},
"index": 74.6,
"grade": "C",
"healthy_at": 80,
"review": {
"id": 311,
"run_id": "RUN-2026-0311",
"finished_at": "2026-10-01T06:02:11Z"
},
"areas": [
{
"area": "Security",
"area_name": "Security",
"score": 68.2,
"checks": 14
},
{
"area": "Cost Efficiency",
"area_name": "Licenses and cost",
"score": 81.0,
"checks": 9
}
],
"projection": {
"base": 74.6,
"quick": {
"n": 6,
"gain": 9.1,
"to": 83.7
}
}
},
"request_id": "req_2c7e4a9f0b1d3e5a6c8b"
}
Tokens and scopes
A token looks like drm_3f9c...: drm_ and 40 hexadecimal characters, the last 8 a checksum, so a mistyped token is refused at once and secret scanners can recognize one. We keep only a fingerprint of it; if a token is lost, replace it.
- Expiry: 30, 90, 180, 365 days (90 by default). The owners get an email and the
token.expiringevent 14 and 3 days before. - Replace: gives a new token with the same access; the old one keeps working for 24 hours so you can switch without downtime. Revoke: stops a token at once.
- Orgs: a token works for all orgs of the account, or only the ones you choose.
- Allowed IP addresses (optional): single IPv4 addresses and ranges ending in /8, /16 or /24.
Each token has scopes. Choose a preset or pick scopes one by one:
| Preset | Scopes |
|---|---|
| Read only | orgs:read, health:read, reviews:read, issues:read, monitoring:read, compliance:read, activity:read |
| Ticketing integration | orgs:read, issues:read, issues:items, issues:write, webhooks:manage |
| Deploy pipeline | orgs:read, health:read, reviews:read, monitoring:read, monitoring:write |
| Full access | orgs:read, orgs:write, health:read, reviews:read, reviews:run, issues:read, issues:items, issues:write, monitoring:read, monitoring:write, compliance:read, activity:read, webhooks:manage |
| Scope | Allows |
|---|---|
orgs:read | See the connected orgs, their connection and planning answers |
orgs:write | Update an org's planning answers |
health:read | Org Health Index, grade, areas, projection, deploy gate, savings and the saved plan |
reviews:read | Reviews, their scores and the 62 checks |
reviews:run | Start an Org Health Review |
issues:read | The issue log (findings and alerts), history and accepted exceptions |
issues:items | The affected items of a check or issue (they can include user names) |
issues:write | Acknowledge, assign, snooze, dismiss, resolve, comment, link tickets, accept exceptions |
monitoring:read | Monitors, alerts and the Security Health Check |
monitoring:write | Open and close deploy windows, re-check a monitor |
compliance:read | SOC 2, HIPAA, ISO 27001, Ontario PHIPA, PIPEDA, GDPR, UK GDPR and Quebec Law 25 evidence and access reviews |
activity:read | The activity log (who did what) |
webhooks:manage | Create and manage webhook endpoints and see deliveries |
Answers and errors
Every answer is JSON (UTF-8). A success has "ok": true and the result in data; an error has "ok": false and an error with a code, the HTTP status it stands for and a message you can show. Every answer carries a request_id; send it to us if something looks wrong.
error.status of its body: 200 for a success, and 401, 403, 404, 409, 422, 429 or 500 for an error, as in the table below. The body is the same JSON either way, so reading ok keeps working. Every answer carries an X-Request-Id header with its request_id, and a rate_limited answer carries Retry-After in seconds. MCP answers use HTTP 200 as JSON-RPC expects, except 401, 403 and 429 when the token check refuses the call. If a proxy or the network answers 502, 503 or 504, wait a few seconds and try again.{
"ok": false,
"error": {
"code": "insufficient_scope",
"status": 403,
"message": "This token does not have the issues:write scope."
},
"request_id": "req_0f2d4b6a8c1e3a5c7e9b"
}
| error.code | status | When |
|---|---|---|
unauthorized | 401 | No token, an unknown, revoked or expired token, or a replaced token after its 24 hours |
plan_required | 403 | The account is not on Professional or Enterprise |
ip_not_allowed | 403 | The token only accepts calls from its allowed IP addresses |
insufficient_scope | 403 | The token lacks the scope the operation needs |
not_found | 404 | Unknown operation, org, review, issue, endpoint or delivery |
conflict | 409 | The request clashes with the current state, for example a review or a deploy window is already running |
invalid | 422 | A parameter is missing or not valid; the message says which |
limit_reached | 429 | A review limit of the plan: one review on demand per org every 24 hours, the org's monthly limit or the account's daily limit; retry_after gives the seconds until the next review can start |
rate_limited | 429 | Too many calls for this token this minute or today; retry_after gives the seconds to wait |
internal | 500 | Something failed on our side; retry, and send us the request_id if it keeps happening |
Send parameters of a GET in the query string. Send a POST as JSON (Content-Type: application/json) with an action and its fields; org may go in the query string or the body. Times are ISO 8601 in UTC. Issue ids look like FND-12 (a finding of a review) or ALR-7 (a monitoring alert); orgs, reviews, endpoints and deliveries have numeric ids.
Limits and paging
| Plan | Tokens | Webhook endpoints | Calls a minute, per token | Calls a day, per token | Reviews on demand, per org every 24 hours | Reviews on demand, per org a month | Reviews on demand, across the account a day |
|---|---|---|---|---|---|---|---|
| Professional | 10 | 5 | 60 | 10,000 | 1 | 20 | 10 |
| Enterprise | 25 | 20 | 300 | 100,000 | 1 | 60 | 25 |
Over a limit, the answer is rate_limited with retry_after in seconds. Reviews started with POST reviews share their limits with the Run review button: over one of them the answer is limit_reached, also with retry_after, and while a review of that org is running it is conflict. The review that runs by itself each month never counts, and Enterprise limits can be set in your agreement. Lists return up to limit items (1 to 200, 50 by default) and a next_cursor; pass it as cursor to get the next page. It is null on the last page.
Reference
Every operation, its scope and its parameters. The OpenAPI file has the full response schemas.
Your token
The calling token: its scopes, orgs, expiry and your plan's limits.
Orgs
orgs:readConnected orgs with their connection, monitoring and latest review; with id, one org and its planning answers.
| Parameter | Type | In | Description |
|---|---|---|---|
id | integer | query | One org |
planning scope orgs:writeUpdate an org's five planning answers.
| Parameter | Type | In | Description |
|---|---|---|---|
org required | integer | body | Org id |
renewal_month | integer | body | Month (1 to 12) the Salesforce contract renews |
retention_notes | string | body | Data you must keep, and for how long |
release_cadence | string | body | How often you release |
known_exceptions | string | body | What is intentional and should stay |
priority | string | body | What matters most |
Org Health
health:readLatest Org Health Index, grade and areas, the trend, what the quick fixes and your decisions would reach, and the saved plan.
| Parameter | Type | In | Description |
|---|---|---|---|
org required | integer | query | Org id (from GET /v1/orgs) (e.g. 12) |
Deploy gate
health:readPass or fail against your thresholds, with the reasons: for deploy pipelines.
| Parameter | Type | In | Description |
|---|---|---|---|
org required | integer | query | Org id (from GET /v1/orgs) (e.g. 12) |
min_grade | string | query | Lowest acceptable grade (e.g. C) |
min_index | number | query | Lowest acceptable Org Health Index (0 to 100) (e.g. 70) |
max_critical | integer | query | Most open critical issues allowed (e.g. 0) |
max_new_critical | integer | query | Most critical issues opened by the latest review or in the last 24 hours (e.g. 0) |
max_drop | number | query | Largest allowed fall of the Index since the previous review (e.g. 5) |
Reviews
reviews:readReviews, newest first; with id, one review with its area scores and links.
| Parameter | Type | In | Description |
|---|---|---|---|
org | integer | query | Only this org (from GET /v1/orgs) (e.g. 12) |
id | integer | query | One review |
cursor | string | query | next_cursor from the previous page |
limit | integer | query | Items per page, 1 to 200 (default 50) (e.g. 50) |
start scope reviews:runStart an Org Health Review; it runs in the background (poll GET /v1/reviews?org=).
| Parameter | Type | In | Description |
|---|---|---|---|
org required | integer | body | Org id |
Checks of a review
reviews:readThe checks of a review with value, status, score, weight and how it gets fixed.
| Parameter | Type | In | Description |
|---|---|---|---|
review required | integer | query | Review id |
status | string | query | Only this status |
include_items | boolean | query | Add the affected items (needs issues:items) |
Review documents
reviews:readA finished review's Executive Brief or Full Review: as text in the answer (the Full Review includes its commentary), or as a PDF download link that works for 15 minutes.
| Parameter | Type | In | Description |
|---|---|---|---|
review required | integer | query | Review id (from GET /v1/reviews) (e.g. 165) |
type | string | query | Which document (default brief) |
format | string | query | text (default) or pdf |
Issues
issues:readFindings (FND-) and alerts (ALR-); with id, one issue with its history, exceptions and how to fix it.
| Parameter | Type | In | Description |
|---|---|---|---|
org | integer | query | Only this org (from GET /v1/orgs) (e.g. 12) |
id | string | query | One issue, for example FND-41 |
status | string | query | open (default: open, acknowledged, snoozed), acknowledged, snoozed, dismissed, resolved or all |
severity | string | query | warn or critical |
kind | string | query | finding or alert |
updated_since | string | query | Only issues changed at or after this ISO time |
include_items | boolean | query | Add the affected items (needs issues:items) |
cursor | string | query | next_cursor from the previous page |
limit | integer | query | Items per page, 1 to 200 (default 50) (e.g. 50) |
acknowledge scope issues:writeAcknowledge an issue, optionally naming the owner.
| Parameter | Type | In | Description |
|---|---|---|---|
id required | string | body | Issue id, e.g. FND-41 |
owner | string | body | Email of a user of your account |
assign scope issues:writeChange the owner.
| Parameter | Type | In | Description |
|---|---|---|---|
id required | string | body | Issue id |
owner required | string | body | Email of a user of your account |
snooze scope issues:writeSnooze until a date.
| Parameter | Type | In | Description |
|---|---|---|---|
id required | string | body | Issue id |
until required | string | body | YYYY-MM-DD |
dismiss scope issues:writeDismiss with a reason.
| Parameter | Type | In | Description |
|---|---|---|---|
id required | string | body | Issue id |
reason required | string | body | Why |
note required | string | body | Details |
resolve scope issues:writeReport it fixed; the next check or review confirms the fix, or reopens the issue.
| Parameter | Type | In | Description |
|---|---|---|---|
id required | string | body | Issue id |
note | string | body | What was done |
reopen scope issues:writeReopen.
| Parameter | Type | In | Description |
|---|---|---|---|
id required | string | body | Issue id |
comment scope issues:writeAdd a note to the history.
| Parameter | Type | In | Description |
|---|---|---|---|
id required | string | body | Issue id |
note required | string | body | The note |
link scope issues:writeLink a ticket of your own system (Jira, ServiceNow, Azure DevOps, ...).
| Parameter | Type | In | Description |
|---|---|---|---|
id required | string | body | Issue id |
ticket_ref required | string | body | Ticket key, e.g. OPS-7 |
ticket_url | string | body | https link to the ticket |
help scope issues:writeAsk for help on it.
| Parameter | Type | In | Description |
|---|---|---|---|
id required | string | body | Issue id |
note | string | body | What you need |
recheck scope issues:writeRe-run the monitor behind an alert now.
| Parameter | Type | In | Description |
|---|---|---|---|
id required | string | body | Alert id, e.g. ALR-12 |
exception scope issues:writeAccept an exception for one affected item, with a reason and a review date.
| Parameter | Type | In | Description |
|---|---|---|---|
id required | string | body | Issue id |
item required | string | body | The item's key (from include_items) |
reason required | string | body | Why it stays |
owner | string | body | Who reviews it |
review_months | integer | body | 3, 6, 12 (default) or 24 |
Monitoring
monitoring:readThe org's monitors with their latest result.
| Parameter | Type | In | Description |
|---|---|---|---|
org required | integer | query | Org id (from GET /v1/orgs) (e.g. 12) |
recheck scope monitoring:writeRe-run one monitor now.
| Parameter | Type | In | Description |
|---|---|---|---|
org required | integer | body | Org id |
key required | string | body | Monitor key |
Security Health Check
monitoring:readSalesforce Security Health Check score history and the settings at risk.
| Parameter | Type | In | Description |
|---|---|---|---|
org required | integer | query | Org id (from GET /v1/orgs) (e.g. 12) |
Deploy windows
monitoring:readDeploy windows of an org.
| Parameter | Type | In | Description |
|---|---|---|---|
org required | integer | query | Org id (from GET /v1/orgs) (e.g. 12) |
open scope monitoring:writeOpen a deploy window: configuration changes during it are expected, not alerts.
| Parameter | Type | In | Description |
|---|---|---|---|
org required | integer | body | Org id |
minutes | integer | body | Length, 5 to 480 (default 60) |
reference | string | body | Your deploy or release reference |
close scope monitoring:writeClose it: the monitors re-check and a summary of the changes is sent to your webhooks.
| Parameter | Type | In | Description |
|---|---|---|---|
org required | integer | body | Org id |
window | integer | body | Window id (default: the open one) |
Compliance
compliance:readControl status and evidence for SOC 2, HIPAA, ISO 27001, Ontario PHIPA, PIPEDA, GDPR, UK GDPR or Quebec Law 25.
| Parameter | Type | In | Description |
|---|---|---|---|
org required | integer | query | Org id (from GET /v1/orgs) (e.g. 12) |
framework | string | query | Framework (default: the first that fits the org, from its own answers or your organization's) (e.g. soc2) |
Evidence exports
compliance:readA signed-off evidence export with its SHA-256, which anyone holding it can verify.
| Parameter | Type | In | Description |
|---|---|---|---|
org required | integer | query | Org id (from GET /v1/orgs) (e.g. 12) |
framework | string | query | Framework (default: the first that fits the org, from its own answers or your organization's) |
Verify an export
Check that an evidence export came from the Command Center (no token needed).
| Parameter | Type | In | Description |
|---|---|---|---|
hash required | string | query | SHA-256 of the export |
Access reviews
compliance:readAccess reviews of admin-level access, their decisions and sign-off.
| Parameter | Type | In | Description |
|---|---|---|---|
org required | integer | query | Org id (from GET /v1/orgs) (e.g. 12) |
Savings and capacity
health:readLicenses you could reclaim and when storage fills up.
| Parameter | Type | In | Description |
|---|---|---|---|
org required | integer | query | Org id (from GET /v1/orgs) (e.g. 12) |
Improvement plan
health:readThe saved improvement plan: each item, its issue and status, projected against achieved.
| Parameter | Type | In | Description |
|---|---|---|---|
org required | integer | query | Org id (from GET /v1/orgs) (e.g. 12) |
Accepted exceptions
issues:readAccepted exceptions with their owner, reason and review date.
| Parameter | Type | In | Description |
|---|---|---|---|
org | integer | query | Only this org (from GET /v1/orgs) (e.g. 12) |
Activity
activity:readWho did what, newest first.
| Parameter | Type | In | Description |
|---|---|---|---|
since | string | query | Only entries at or after this ISO time |
cursor | string | query | next_cursor from the previous page |
limit | integer | query | Items per page, 1 to 200 (default 50) (e.g. 50) |
Webhooks
webhooks:manageYour webhook endpoints.
create scope webhooks:manageAdd an endpoint; the signing secret is returned once.
| Parameter | Type | In | Description |
|---|---|---|---|
url required | string | body | https URL |
events | string | body | Comma-separated events, or all |
description | string | body | What it is for |
delete scope webhooks:manageRemove an endpoint.
| Parameter | Type | In | Description |
|---|---|---|---|
endpoint required | integer | body | Endpoint id |
rotate scope webhooks:manageNew signing secret (returned once).
| Parameter | Type | In | Description |
|---|---|---|---|
endpoint required | integer | body | Endpoint id |
test scope webhooks:manageSend a webhook.test event.
| Parameter | Type | In | Description |
|---|---|---|---|
endpoint required | integer | body | Endpoint id |
redeliver scope webhooks:manageSend one delivery again.
| Parameter | Type | In | Description |
|---|---|---|---|
delivery required | integer | body | Delivery id |
enable scope webhooks:manageTurn an endpoint on or off.
| Parameter | Type | In | Description |
|---|---|---|---|
endpoint required | integer | body | Endpoint id |
enabled required | boolean | body | true or false |
Webhook deliveries
webhooks:manageDeliveries, newest first, with status and attempts.
| Parameter | Type | In | Description |
|---|---|---|---|
endpoint | integer | query | Only this endpoint |
status | string | query | pending, retrying, delivered or failed |
cursor | string | query | next_cursor from the previous page |
limit | integer | query | Items per page, 1 to 200 (default 50) (e.g. 50) |
Webhooks
Add an endpoint on the API access page or with POST /v1/webhooks (action create). The URL must use https and a public host name. You get the endpoint's signing secret once; a new one replaces it at once (rotate).
We POST each event as JSON with these headers: Dream-Event (the type), Dream-Event-Id, Dream-Delivery, Dream-Timestamp and Dream-Signature: t=<unix time>,v1=<hex>, where v1 is the HMAC-SHA256 of <t>.<body> with the endpoint's secret. Check it on the exact bytes you received, and refuse a timestamp older than five minutes.
import hashlib, hmac, time
def dream_signature_ok(secret: str, header: str, body: bytes, tolerance: int = 300) -> bool:
parts = dict(p.split("=", 1) for p in header.split(",") if "=" in p)
t, v1 = parts.get("t", ""), parts.get("v1", "")
if not t.isdigit() or abs(time.time() - int(t)) > tolerance:
return False
want = hmac.new(secret.encode(), t.encode() + b"." + body, hashlib.sha256).hexdigest()
return hmac.compare_digest(want, v1)const crypto = require("crypto");
function dreamSignatureOk(secret, header, rawBody, tolerance = 300) {
const parts = Object.fromEntries(header.split(",").map((p) => p.split("=", 2)));
const t = parts.t || "", v1 = parts.v1 || "";
if (!/^\d+$/.test(t) || Math.abs(Date.now() / 1000 - Number(t)) > tolerance) return false;
const want = crypto.createHmac("sha256", secret).update(t + "." + rawBody).digest("hex");
return want.length === v1.length && crypto.timingSafeEqual(Buffer.from(want), Buffer.from(v1));
}
Answer with any 2xx within 10 seconds. Otherwise we try again after 1, 5, 30, 120, 360 and 720 minutes, then daily, for 3 days; after that the delivery is marked failed. You can send any delivery again from the API access page or with redeliver. A delivery can arrive twice or out of order: use Dream-Event-Id to skip one you have seen.
{
"id": "evt_6b1f0c9e2d4a8b3f7e5c1a0d",
"type": "issue.opened",
"created_at": "2026-10-02T09:14:05Z",
"api_version": "v1",
"account": {
"id": 42,
"name": "Example Co"
},
"data": {
"issue": {
"id": "ALR-318",
"kind": "alert",
"org": 12,
"title": "Users with Modify All Data",
"check": "sec.modify_all_users",
"area": "Security",
"area_name": "Security",
"severity": "critical",
"status": "open",
"value_text": "9 users have Modify All Data",
"opened_at": "2026-10-02T09:14:02Z",
"resolved_at": null,
"resolved_by": null,
"due_at": "2026-10-05T09:14:02Z",
"owner": null,
"ticket": null,
"verify_state": null,
"link": "https://health.dream.cloud/app/issue.html?id=ALR-318"
},
"org": {
"id": 12,
"name": "Example Co Production"
},
"note": null
}
}
| Event | When |
|---|---|
review.completed | A review finished and was scored |
health.grade_changed | A review gave a different grade than the previous review |
health.index_dropped | The Org Health Index fell by 5 points or more since the previous review |
issue.opened | A review or a monitor opened a finding or an alert |
issue.updated | Someone acknowledged, assigned, snoozed, dismissed, commented on or linked an issue |
issue.resolved | An issue was resolved (by a check, a review, a person, Jira or the API) |
issue.reopened | A resolved issue came back, or a fix was not confirmed by the next check |
issue.overdue | An open issue passed its due date |
issue.fix_confirmed | The next check or review confirmed a fix that a person or ticket reported |
plan.item_done | An item of the saved improvement plan was fixed |
exception.expiring | An accepted exception reaches its review date within 14 days |
exception.expired | An accepted exception passed its review date and counts again |
connection.expired | Salesforce refused the stored connection; the org needs to be reconnected |
deploy_window.closed | A deploy window closed; the changes it covered are summarized |
token.expiring | An API token expires within 14 days |
token.leaked | GitHub found an API token in a public place; it was revoked at once |
webhook.test | A test event sent from the API access page or the API |
MCP server
AI assistants that speak the Model Context Protocol can use the Command Center through its MCP server: streamable HTTP with JSON answers, protocol versions 2025-06-18, 2025-03-26 and 2024-11-05. Send the API token as a header; the assistant sees only the tools the token's scopes allow.
https://health.dream.cloud/v1/mcp
Claude Code
claude mcp add --transport http dream https://health.dream.cloud/v1/mcp --header "Authorization: Bearer drm_your_token"
Cursor (~/.cursor/mcp.json)
{
"mcpServers": {
"dream": {
"url": "https://health.dream.cloud/v1/mcp",
"headers": {
"Authorization": "Bearer drm_your_token"
}
}
}
}
VS Code (.vscode/mcp.json; VS Code asks for the token once and stores it)
{
"inputs": [
{
"type": "promptString",
"id": "dream-token",
"description": "Dream API token",
"password": true
}
],
"servers": {
"dream": {
"type": "http",
"url": "https://health.dream.cloud/v1/mcp",
"headers": {
"Authorization": "Bearer ${input:dream-token}"
}
}
}
}
Custom connectors in Claude.ai and ChatGPT sign in with OAuth, which the Command Center does not offer yet; use an assistant that can send a header, such as the ones above.
| Tool | What it does |
|---|---|
list_orgs | List the connected Salesforce orgs with their latest Org Health Index and grade. |
get_org_health | Org Health Index, grade, the five areas, the trend and what the quick fixes and decisions would reach. |
check_deploy_gate | Check an org against deploy thresholds (grade, index, critical issues, drop) and say why it passes or fails. |
list_reviews | List Org Health Reviews, newest first. |
list_review_checks | The checks of one review with value, status and score. |
get_review_document | A finished review's Executive Brief (type brief, the default) or Full Review (type full) as plain text, including its written commentary. Find the review id with list_reviews. |
list_issues | List open findings and alerts (or another status), newest first. |
get_issue | One issue with its history, accepted exceptions and how to fix it. |
list_monitors | The org's monitors with their latest result. |
get_health_check | Salesforce Security Health Check score and settings at risk. |
get_compliance | SOC 2, HIPAA, ISO 27001, Ontario PHIPA, PIPEDA, GDPR, UK GDPR or Quebec Law 25 control status and evidence. |
get_savings | Licenses you could reclaim and when storage fills up. |
get_plan | The saved improvement plan and its progress. |
list_activity | Who did what in the Command Center, newest first. |
start_review | Start an Org Health Review of an org (runs in the background). |
acknowledge_issue | Acknowledge an issue, optionally naming the owner by email. |
assign_issue | Change an issue's owner (email of a user of the account). |
snooze_issue | Snooze an issue until a date (YYYY-MM-DD). |
comment_on_issue | Add a note to an issue's history. |
link_ticket | Link a ticket from your own system to an issue. |
resolve_issue | Report an issue fixed; the next check or review confirms it or reopens it. |
open_deploy_window | Open a deploy window so configuration changes during it are expected. |
close_deploy_window | Close the org's open deploy window and re-check. |
Recipes
Stop a deployment when an org's health drops
Call /gate before you deploy. It answers pass with the rules you set: min_grade, min_index, max_critical, max_new_critical, max_drop. Open a deploy window around the deployment so the changes it makes count as expected, not as changes outside your release windows; closing it re-checks security and sends deploy_window.closed with a summary.
# GitHub Actions: a step before the deploy (the token is a repository secret)
- name: Check org health
env:
DREAM_TOKEN: ${{ secrets.DREAM_TOKEN }}
DREAM_API: https://health.dream.cloud/v1
run: |
curl -s -H "Authorization: Bearer $DREAM_TOKEN" "$DREAM_API/gate?org=12&min_grade=B&max_new_critical=0" > gate.json
jq -e '.ok and .data.pass' gate.json || { jq '.data.reasons // .error' gate.json; exit 1; }
curl -s -X POST -H "Authorization: Bearer $DREAM_TOKEN" -H "Content-Type: application/json" \
-d '{"action": "open", "org": 12, "minutes": 60, "reference": "release ${{ github.sha }}"}' "$DREAM_API/windows"
The same two calls work from Gearset, Copado, Azure Pipelines or any tool that can run a script or an HTTP request. Close the window with {"action": "close", "org": 12} when the deployment ends.
Tickets in Jira, ServiceNow or Azure DevOps
The Command Center already creates Jira Cloud and ServiceNow tickets from the Issues page (Settings). To run your own flow instead: subscribe an endpoint to issue.opened, create the ticket, then link it back with POST /v1/issues action link (ticket_ref, ticket_url). Resolve the issue with action resolve when the ticket closes: the next check confirms the fix (issue.fix_confirmed) or reopens the issue (issue.reopened).
Slack and Microsoft Teams
Alerts can go to Slack and Teams without code (Settings > Notifications). For your own messages, send webhook events through a small relay (for example a serverless function) that checks the signature and posts to your channel.
Power BI, Tableau and spreadsheets
Point a web data source at /health, /reviews or /issues with the header Authorization: Bearer ... and a read-only token. In Power BI: Get data > Web > Advanced, add the header, then expand data.
Splunk and Microsoft Sentinel
Poll /activity?since=... every few minutes for the audit trail (who did what, and when), or relay webhook events to your HTTP event collector.
Compliance tools such as Drata and Vanta
/evidence returns the evidence for SOC 2, HIPAA, ISO 27001, Ontario PHIPA, PIPEDA, GDPR, UK GDPR or Quebec Law 25 (by default the first that fits the org) with its sha256; anyone can check an export with /verify?hash=..., no token needed. Attach the export and the verification link to your control.
Salesforce External Services
Use the API from Salesforce Flow without code. Import openapi-salesforce.json, a subset (orgs, health, gate, issues) written for External Services.
- External Credential (Setup > Named Credentials > External Credentials): authentication protocol Custom. Add a principal with an authentication parameter named
tokenholding your API token, and a custom headerAuthorizationwith the value{!'Bearer ' & $Credential.Dream_API.token}(use your External Credential's API name). - Named Credential: URL
https://health.dream.cloud/v1, the External Credential above, Allow Formulas in HTTP Header on and Generate Authorization Header off. - Give the users or the flow's running user access to the principal in a permission set (External Credential Principal Access).
- External Services: add a service from the API specification file, choose the Named Credential and the operations. They then appear as actions in Flow Builder.
Every answer has ok: branch on it in the flow, because errors also come back as success at the HTTP level.
Files
- openapi.json: OpenAPI 3.0, every operation with its response schema, and the webhook events
- openapi-salesforce.json: the subset for Salesforce External Services
- postman.json: a Postman collection; set the
tokenandorgvariables - llms.txt: a short index for AI tools
Versions
The version is in the path (/v1). We add fields, operations and events without notice, so ignore what you do not know. Anything that would break a client comes in a new version, announced here in advance.
Version 1.0.0 · Questions: contact us · Terms · Privacy Policy