Agent API (v2.0)
The Agent API allows AI agents to take direct action in Sitecore through secure REST endpoints. It supports common digital experience tasks such as creating pages, adding components, and updating content.
As part of Sitecore's interoperability approach, the Agent API allows agentic platforms and other connected systems to interact directly with Sitecore. When an AI agent receives a natural language request, it can call the appropriate Agent API endpoints to complete the task. For example, a request to create a new landing page might trigger an endpoint in Sitecore that automatically builds the page. If the AI agent performs an unintended action, you can use the job ID to revert it. Each operation is tracked to ensure safe rollback when needed.
All Agent API actions follow the built-in security and approval rules in Sitecore, keeping work safe, traceable, and auditable.
In addition to AI agent-driven workflows, developers can also use the REST API directly to interact with the following objects:
- Sites - retrieve and manage sites and their pages.
- Pages - create and manage pages and components.
- Content - create and organize content items.
- Components - retrieve and manage components and datasources.
- Assets - upload and manage digital assets.
- Environments - retrieve environment and language details.
- Personalization - manage personalized content variants.
- Jobs - view or revert job operations.
- Brand kits - retrieve brand kits and their details.
- Brand contexts - retrieve brand contexts, their metadata, folder and file trees, and content.
- Briefs - retrieve brief types, generate and create briefs.
- Experiments - create and update A/B tests on components on a page.
- Flow definitions - retrieve flow definitions (A/B/n tests and personalizations) for a page and set up their variants.
Note the following:
- To use this REST API, you authenticate your API requests.
- All API requests are made in your production environment.
The Agent API also powers the Sitecore Marketer MCP server, which uses these endpoints to perform agentic operations in Sitecore. Read more about the Marketer MCP server.
To authorize your requests, use environment automation client credentials and generate a JSON Web Token (JWT). You can also register an OAuth app if your integration requires the OAuth 2.0 authorization code flow.
Note: To create client credentials, you must be an Organization Admin or Organization Owner.
- In the Sitecore Cloud Portal, open SitecoreAI Deploy.
- Click Credentials > Environment > Create credentials > Automation.
- Fill out the automation client details, then click Create.
- Copy the client ID and the client secret because you won't be able to view them again in SitecoreAI Deploy. You'll use them to request a JWT.
The Agent API uses the OAuth 2.0 authorization code flow to securely authenticate requests from external applications.
Each application must have an OAuth app registration, which identifies the app and defines the parts of the Sitecore platform it can access.
If you plan to register an OAuth app that uses the Agent API, you must submit a registration request to Sitecore Support and request the following scopes:
xmcloud.cm:adminpersonalize.exp:mngpersonalize.tmpl:rpersonalize.pos:mngai.org.bri:rco.briefs:rco.briefs:wai.org.brd:rai.org.bri:wcmp.sites:readplatform.tenants:list
Run the following cURL command to request a JWT. Replace the placeholder values with your client ID and client secret.
curl -X POST 'https://auth.sitecorecloud.io/oauth/token' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'client_id={YOUR_CLIENT_ID}' \
--data-urlencode 'client_secret={YOUR_CLIENT_SECRET}' \
--data-urlencode 'grant_type=client_credentials' \
--data-urlencode 'audience=https://api.sitecorecloud.io'In the response, the access_token key contains the JWT:
{
"access_token": "{YOUR_JWT}",
"scope": "xmcloud.cm:admin",
"expires_in": 86400,
"token_type": "Bearer"
}The JWT expires in 24 hours. If your requests unexpectedly return a response with status 401 Unauthorized, request a new JWT by repeating this POST request.
We recommend that you cache the JWT for 24 hours to avoid repeating this POST request while the JWT is still valid.