---
title: "Query AI Indices"
method: POST
path: "/api/context_engine/ai_index/_query"
tags: ["context engine"]
---

# Query AI Indices

`POST /api/context_engine/ai_index/_query`

**Spaces method and path for this operation:**

<div><span class="operation-verb post">post</span>&nbsp;<span class="operation-path">/s/{space_id}/api/context_engine/ai_index/_query</span></div>

Refer to [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces) for more information.

Runs an ES|QL query as the current user. The server applies a space filter and limits the response to at most 1000 rows.

The query determines which indices it reads. Elasticsearch index privileges limit which indices the current user can access.

The space comes from the request URL (`/s/{spaceId}/…`) or defaults to the default space. The request body cannot change the space or replace the space filter.

Returns a 404 response when Context Engine is turned off in this space (`contextEngine:enabled`).

**For more information, refer to the [Context Engine documentation](https://www.elastic.co/docs/explore-analyze/ai-features/context-engine).**<br/><br/>[Required authorization] Route required privileges: contextEngine:read.

## Headers

- `kbn-xsrf` string, required

## Request body

- object
  - `limit` number — Maximum rows to return. Defaults to 100; a trailing `LIMIT` in the query is capped to this value.
  - `params` object — Values for `?name` placeholders in the query.
  - `query` string, required — The ES|QL query to run. Its FROM decides which Elasticsearch indices are read (normally `ai-index-*`); the server adds the space filter and a row limit.

## Response `200`

The columns and rows returned by the ES|QL query.

- object
  - `columns` object[], required — Column metadata for the returned rows.
    - `name` string, required — Column name.
    - `type` string, required — Column ES|QL type.
  - `values` array[], required — Row values, aligned positionally with `columns`, as Elasticsearch returns them. A multi-valued field is an array; `_source` and `flattened` columns are objects.
    - unknown[]
      - unknown

## Other responses

- `400` — The ES|QL query was invalid, or its response exceeded the size limit.
- `403` — Elasticsearch rejected the read; the caller lacks index privileges.
- `404` — Context Engine is turned off in this space.

---

[API](https://skmtc.dev/elastic/apis/kibana-apis.md) · [All operations](https://skmtc.dev/elastic/apis/kibana-apis/llms.txt) · [OpenAPI document](https://skmtc.dev/elastic/apis/kibana-apis/revisions/a6aad934034f?raw)
