# SNOK developer resources - API, OpenAPI and llms.txt

> SNOK developer resources: machine-readable files, the OpenAPI description of the snok.ai form endpoints, authentication, versioning, rate limits and examples.

- Source: https://snok.ai/en/developers/

---

# SNOK developer resources

Machine-readable files and the public endpoints behind the forms on snok.ai.

## What this API is

The snok.ai site does not offer a product or integration API. The endpoints below serve the forms on this site and we publish their contract so that it is open and verifiable. For enquiries about SNOK's services, please use the [contact form](https://snok.ai/en/contact/) or email [office@snok.ai](mailto:office@snok.ai). AI agents will find a guide in [/llms.txt](https://snok.ai/llms.txt).

## Machine-readable resources

- [/openapi.json](https://snok.ai/openapi.json) - OpenAPI 3.1 description of every public endpoint, error codes and headers.
- [/llms.txt](https://snok.ai/llms.txt) and [/llms-full.txt](https://snok.ai/llms-full.txt) - SNOK's competences, services and contact details for AI agents.
- Markdown variant of every page: send `Accept: text/markdown` or append `index.md` to the page URL.
- [/sitemap.xml](https://snok.ai/sitemap.xml), [/rss.xml](https://snok.ai/rss.xml) (Polish) and [/en/rss.xml](https://snok.ai/en/rss.xml) (English).

## Endpoints

Version 2026-10-07. Request and response schemas are in [/openapi.json](https://snok.ai/openapi.json); every path ends with a trailing slash.

- `POST /api/contact/` (submitContactForm)
- `POST /api/apply/` (submitJobApplication)
- `POST /api/ksc-check/score/` (scoreKscCheck)
- `POST /api/ksc-check/submit/` (requestKscCheckReport)
- `POST /api/materials/request/` (requestGatedMaterial)
- `GET /api/materials/download/` (downloadGatedMaterial)

## Authentication

Reading the files above needs no authentication. The form endpoints accept requests only from the snok.ai origin and, apart from the KSC-CHECK score, only with a one-time Cloudflare Turnstile token issued to the form in a browser. An agent cannot obtain that token, so these endpoints cannot be called programmatically - by design. Requests from another origin receive `403 origin_forbidden`.

## Versioning and deprecation

Every JSON response under `/api/` carries `API-Version: 2026-10-07`, the same value as `info.version` in the specification. A client may pin a version by sending `API-Version` with a date; any date up to and including the current version is served. A later date or a malformed value returns `400 unsupported_version`. A breaking change gets a new path, and the old one keeps working for at least 90 days with `Deprecation` (RFC 9745) and `Sunset` (RFC 8594) headers. No operation is deprecated today.

## Rate limits

Limits apply per IP address and per endpoint. Responses carry `RateLimit` and `RateLimit-Policy` (draft-ietf-httpapi-ratelimit-headers-11) as well as `RateLimit-Limit`, `RateLimit-Remaining` and `RateLimit-Reset`; a `429 rate_limited` response adds `Retry-After`. The counter runs in the memory of each serverless instance, so the declared limit is the ceiling a client should respect.

## Errors

Every error is JSON with a stable machine-readable `code`, a human-readable `error` in the form's language, an English `hint` on how to fix the request and the RFC 9457 fields `type`, `title` and `status`. Unknown paths under `/api/` return `404 not_found`; a method outside the contract returns `405 method_not_allowed` with an `Allow` header.

## Examples

Fetch the specification:

```
`curl -s https://snok.ai/openapi.json`
```

Read a page as Markdown:

```
`curl -s -H 'Accept: text/markdown' https://snok.ai/en/offer/`
```

Check the contract of an endpoint without submitting anything (405 with `Allow: POST` and `API-Version`):

```
`curl -si https://snok.ai/api/contact/`
```
