ConventionsAISafe REST endpoints share a set of cross-cutting rules: base URLs, authentication, pagination, error handling, rate limits, and identifier formats. For per-endpoint reference, see the API Reference.AuthAISafe API authentication uses Bearer tokens in the Authorization header.ErrorsAISafe API errors use a consistent envelope.WebhooksAISafe outbound webhooks deliver real-time notifications when important events occur: assessments completing, findings discovered or changing status, reports ready, monitoring regressions detected, and spend guardrails crossing thresholds. Subscribe to events and AISafe delivers signed HTTP POST requests to your endpoint.Reference36 items