Base URL
Authentication
Every request carries a bearer token:ad_) is scoped to a single
application and identifies it, so no application id is ever sent. An account
token (adu_) represents you, can create applications, and therefore has to
name the one it is acting on with ?applicationId=<id>.
Authentication
Both credentials, what each can do, rotating and revoking.
Terminal login
How an agent gets an account token without a browser.
Endpoints
That is the complete surface. Deleting an application is deliberately not on
it: that needs the dashboard, so no credential sitting in a project directory
can destroy one.
Deploy over the API
The full deploy reference, with the one command that ships a directory.
Request format
POST /api/v1/deploy is multipart/form-data: it carries your source
tree. Everything else is JSON.
Rate limits
A second deploy while one is running returns
409 with the in-flight
taskId, not an error you need to retry blindly. Exceeding the hourly limit
returns 429 with retryAfterSeconds.
Both limits exist because agents retry. A human clicks Deploy a few times a
day; a loop that treats failure as retryable will hit the API as fast as it is
accepted.
Errors
Errors return a JSON body with a stablecode, a human-readable error, and
a documentation URL pointing back at the contract.
Match on
code, not on the message text.
Two carry more than a message, and are worth reading rather than just relaying:
too_large lists every offending path in files, and name_taken returns the
applicationId you already have, so a script can use it instead of failing.
Asynchronous by design
POST /api/v1/deploy returns 202 immediately with a taskId. Building and
releasing take a minute or two. Poll /api/v1/deployments/{taskId} until
status is succeeded or failed.
The poll response carries warnings and hazards as structured data. A
deploy can succeed and still not behave as its author expects; those fields
are how you find out.