> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ankra.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Every move on the cost line, named by what happened

> The events that moved the organisation's cost run rate over the last `days` UTC days (`ankra cost events`), newest first, in the caller's display currency: application releases (version changes in the clusters' resource graphs), node-count changes between adjacent priced hours, scheduled and manual stops and starts, executed cost decisions, clusters entering or leaving pricing, and resolved cloud waste. A snapshot-measured event carries window_delta_monthly_cents, how the cluster's run rate moved between the priced hour before it and the first priced hour at least 30 minutes after it; delta_monthly_cents is set only when the event was alone in that window (delta_status isolated). Events sharing a window are shared: each carries the window's move and none claims a share of it. no_snapshots means no priced hour on one side, so the move is unknown, never zero. A coverage event's delta is coverage, not spend; a resolved finding's is its own monthly cost (own_cost), or unknown (unpriced). sources says which kinds could be read; a kind marked unavailable is missing from events, not quiet. At most 500 events (truncated). Bearer-PAT twin of the browser route of the same name under /org.



## OpenAPI

````yaml https://platform.ankra.app/openapi.json get /api/v1/org/cloud-cost/events
openapi: 3.1.0
info:
  title: FastAPI
  version: 0.1.0
servers:
  - url: https://platform.ankra.app
security: []
tags:
  - name: Clusters
    description: Create, inspect and manage clusters, and the stacks deployed on them.
  - name: Managed Clusters
    description: Provider-managed control planes, driven through one common surface.
  - name: Imported Clusters
    description: Clusters that already existed and were connected to Ankra.
  - name: Cluster Access
    description: Kubeconfigs, service-account tokens and per-cluster access grants.
  - name: Kubernetes
    description: Read and act on the Kubernetes objects inside a cluster.
  - name: AWS Clusters
    description: >-
      Provision and manage self-managed k3s / kubeadm clusters on AWS EC2 in
      your own VPC.
  - name: DigitalOcean Clusters
    description: Provision and manage DigitalOcean Kubernetes clusters.
  - name: Hetzner Clusters
    description: Provision and manage Hetzner Kubernetes clusters.
  - name: OVH Clusters
    description: Provision and manage OVH Kubernetes clusters.
  - name: Scaleway Clusters
    description: Provision and manage Scaleway Kapsule clusters.
  - name: UpCloud Clusters
    description: Provision and manage UpCloud Kubernetes clusters.
  - name: Applications
    description: Deploy, configure and observe applications across the fleet.
  - name: Backups
    description: >-
      Backup vaults, restore points, protection posture and captures for stacks
      and application deployments; a completed capture is not a verified
      restore.
  - name: Stack Profiles
    description: Reusable stack definitions, their versions and sharing.
  - name: Services
    description: >-
      Versioned service packages and explicit sharing. Runtime admission is
      separate from publication.
  - name: Charts
    description: Browse the chart catalogue behind stacks and addons.
  - name: Helm
    description: Helm registries, credentials and the charts they expose.
  - name: Executions
    description: Long-running platform executions and their jobs.
  - name: Operations
    description: Cancel in-flight cluster operations and their jobs.
  - name: Chat
    description: Conversational sessions, plans and confirmable actions.
  - name: AI Agent Runs
    description: Autonomous agent runs and their outcomes.
  - name: AI Tickets
    description: The AI ticket board, its sync connections and settings.
  - name: AI Playbooks
    description: Reusable playbooks the AI lanes execute.
  - name: AI Conditions
    description: Conditions that gate AI autonomy.
  - name: AI Remediation
    description: >-
      The organisation's auto-remediation policy: what the AI lanes may fix by
      themselves, and who approves the rest.
  - name: AI Engineering Handoffs
    description: Work the AI lanes escalate to a human engineer.
  - name: AI Environment
    description: The environment and base stacks AI demos deploy into.
  - name: Security
    description: Findings, advisories, SBOMs, compliance and posture.
  - name: Cost
    description: Cluster and fleet cost, rate cards and cost settings.
  - name: Decisions
    description: >-
      The decision ledger behind the Security and Cost queues: proposals a
      surface computed, the approve and set-aside decisions people took on them,
      and the receipts of running them.
  - name: Billing
    description: Subscription and spend caps.
  - name: Organisation
    description: Members, invitations, audit logs and organisation settings.
  - name: Account Tokens
    description: Personal access tokens for the API and CLI.
  - name: Credentials
    description: The shared credential store.
  - name: AWS Credentials
    description: >-
      AWS credentials: access keys or CloudFormation-onboarded STS roles for
      cost, EKS and self-managed provisioning.
  - name: Azure Credentials
    description: Azure credentials and SSH keys.
  - name: DigitalOcean Credentials
    description: DigitalOcean credentials and SSH keys.
  - name: Hetzner Credentials
    description: Hetzner credentials and SSH keys.
  - name: OVH Credentials
    description: OVH credentials and SSH keys.
  - name: Scaleway Credentials
    description: Scaleway credentials.
  - name: UpCloud Credentials
    description: UpCloud credentials and SSH keys.
  - name: Data Source Credentials
    description: Credentials for metrics and log sources.
  - name: DNS Credentials
    description: Credentials for DNS providers.
  - name: Object Storage Buckets
    description: >-
      Buckets Ankra creates and manages on an organisation's own provider
      credentials.
  - name: DNS
    description: DNS zones and records, including custom organisation zones.
  - name: Cloudflare
    description: Cloudflare domains and the credentials behind them.
  - name: Variables
    description: Organisation- and cluster-scoped variables.
  - name: SOPS
    description: Encrypt and decrypt values with the organisation SOPS config.
  - name: Alerts
    description: Alert integrations and ingest credentials.
  - name: Notifications
    description: Notification routes and their delivery targets.
  - name: Support
    description: Support tickets.
  - name: AI Settings
    description: Organisation AI provider, model catalog and per-function model settings
paths:
  /api/v1/org/cloud-cost/events:
    get:
      tags:
        - Cost
      summary: Every move on the cost line, named by what happened
      description: >-
        The events that moved the organisation's cost run rate over the last
        `days` UTC days (`ankra cost events`), newest first, in the caller's
        display currency: application releases (version changes in the clusters'
        resource graphs), node-count changes between adjacent priced hours,
        scheduled and manual stops and starts, executed cost decisions, clusters
        entering or leaving pricing, and resolved cloud waste. A
        snapshot-measured event carries window_delta_monthly_cents, how the
        cluster's run rate moved between the priced hour before it and the first
        priced hour at least 30 minutes after it; delta_monthly_cents is set
        only when the event was alone in that window (delta_status isolated).
        Events sharing a window are shared: each carries the window's move and
        none claims a share of it. no_snapshots means no priced hour on one
        side, so the move is unknown, never zero. A coverage event's delta is
        coverage, not spend; a resolved finding's is its own monthly cost
        (own_cost), or unknown (unpriced). sources says which kinds could be
        read; a kind marked unavailable is missing from events, not quiet. At
        most 500 events (truncated). Bearer-PAT twin of the browser route of the
        same name under /org.
      operationId: cloud_cost_events_api_v1_org_cloud_cost_events_get
      parameters:
        - description: PAT organisation override.
          in: header
          name: x-ankra-organisation-id
          required: false
          schema:
            type: string
        - in: query
          name: days
          required: false
          schema:
            default: 30
            maximum: 34
            minimum: 1
            type: integer
          description: >-
            How many UTC days the trend covers, ending today (1..34: the cost
            snapshots are kept 35 days).
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CostEventsResponse'
          description: Successful response
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContractDetailError'
          description: >-
            Missing or malformed Authorization header, days out of range, or
            business validation error
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContractDetailError'
          description: Unknown, expired, or revoked API token
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContractDetailError'
          description: >-
            Token may not use this surface (MCP-scoped token or service account
            restriction)
        '422':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
          description: Request validation error
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContractDetailError'
          description: Internal server error
      security:
        - BearerAuth: []
components:
  schemas:
    CostEventsResponse:
      description: Every move on the cost line, named by what happened (ankra-cozgu.1.7.3).
      properties:
        currency:
          type: string
        generated_at:
          type: string
          format: date-time
        days:
          type: integer
        events:
          items:
            $ref: '#/components/schemas/CostEvent'
          type: array
          description: Newest first.
        truncated:
          type: boolean
          description: More than 500 events; the newest 500 are served.
        sources:
          items:
            $ref: '#/components/schemas/CostEventSource'
          type: array
          description: >-
            Which kinds of event could be read; an unavailable kind is missing
            from events, not quiet.
      required:
        - currency
        - generated_at
        - days
        - events
        - truncated
        - sources
      title: CostEventsResponse
      type: object
    ContractDetailError:
      example:
        detail: Cluster not found
      properties:
        detail:
          oneOf:
            - type: string
            - additionalProperties: true
              properties: {}
              type: object
      required:
        - detail
      type: object
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          title: Detail
          type: array
      title: HTTPValidationError
      type: object
    CostEvent:
      description: One thing that happened, and what it did to the run rate.
      properties:
        at:
          type: string
          format: date-time
        day:
          format: date
          type: string
        kind:
          type: string
          enum:
            - application_release
            - node_count
            - power_schedule
            - power_manual
            - decision
            - coverage
            - waste_resolved
        cluster_id:
          anyOf:
            - type: string
              format: uuid
            - type: 'null'
          description: Null for account-level events (most resolved waste).
        cluster_name:
          anyOf:
            - type: string
            - type: 'null'
          description: The cluster's name when it is known.
        subject:
          type: string
          description: >-
            What happened, e.g. "Commerce 2.13 → 2.14", "3 → 5 nodes",
            "Scheduled stop".
        actor:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Who did it, when a person did: a manual stop's user, a decision's
            decider.
        delta_monthly_cents:
          anyOf:
            - type: integer
            - type: 'null'
          description: >-
            This event's own move: set when it was alone in its window
            (isolated), the cluster's coverage (coverage) or the finding's cost
            (own_cost). Null otherwise; never zero for unknown.
        window_delta_monthly_cents:
          anyOf:
            - type: integer
            - type: 'null'
          description: >-
            How the cluster's run rate moved between the priced hour before the
            event and the first priced hour at least 30 minutes after it,
            whether or not other events shared the window. Null without both.
        delta_status:
          type: string
          enum:
            - isolated
            - shared
            - no_snapshots
            - coverage
            - own_cost
            - unpriced
        note:
          type: string
      required:
        - at
        - day
        - kind
        - cluster_id
        - cluster_name
        - subject
        - actor
        - delta_monthly_cents
        - window_delta_monthly_cents
        - delta_status
        - note
      title: CostEvent
      type: object
    CostEventSource:
      description: One kind of event and whether it could be read.
      properties:
        kind:
          type: string
        available:
          type: boolean
      required:
        - kind
        - available
      title: CostEventSource
      type: object
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          title: Location
          type: array
        msg:
          title: Message
          type: string
        type:
          title: Error Type
          type: string
      required:
        - loc
        - msg
        - type
      title: ValidationError
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: PAT
      scheme: bearer
      type: http

````