temperDocs
Menu

API reference

Schemas

Every object the API sends or accepts, as defined in the OpenAPI spec.

AcquireBrowserLeaseRequest

FieldTypeDescription
environment_idrequiredstring
profile_idstring | null

Omit for a clean browser

modeBrowserLeaseMode | null

With a profile, defaults to write and cannot be clean; without a profile, it can only be clean (or omitted).

ActionCategory

Action category. send, pay, delete and change_permission are high-risk categories that rules cannot allow; they always require approval.

"read" | "write" | "send" | "pay" | "delete" | "change_permission"

AddMemberRequest

FieldTypeDescription
emailrequiredstring
rolerequiredMemberRole

owner: manages members, API keys and the webhook, plus everything a member can do; member: day-to-day operations.

namestring | null

AgentSettings

Defaults: on, 20 schedules, minimum interval 900 seconds, 7200 seconds per keep-awake, 21600 seconds of keep-awake per 24 hours.

FieldTypeDescription
schedulingrequiredboolean
max_schedulesrequiredinteger
min_interval_secsrequiredinteger
keep_awake_max_secsrequiredinteger
keep_awake_daily_secsrequiredinteger

AgentSettingsPatch

FieldTypeDescription
schedulingboolean

false = the Agent cannot register schedules or keep-awake

max_schedulesinteger
min_interval_secsinteger
keep_awake_max_secsinteger
keep_awake_daily_secsinteger

ApiKey

FieldTypeDescription
idrequiredstring
namerequiredstring | null

Keys issued by the platform operator have no name.

prefixrequiredstring

The first few characters of the key (temper_sk_...), for identifying it.

created_atrequiredstring (date-time)
created_byrequiredstring | null

Who created it (member email; null for keys issued by the platform operator).

last_used_atrequiredstring (date-time) | null
revoked_atrequiredstring (date-time) | null

ApiKeyList

FieldTypeDescription
datarequiredarray of ApiKey

Approval

FieldTypeDescription
idrequiredstring
environment_idrequiredstring
connectorrequiredstring
categoryrequiredActionCategory

Action category. send, pay, delete and change_permission are high-risk categories that rules cannot allow; they always require approval.

summaryrequiredstring

A one-sentence summary shown to the end user.

session_idrequiredstring | null
task_idrequiredstring | null
max_scoperequiredScopeKind

Grant scope, from narrowest to widest: once < task < session < time_limited < permanent. Note: in a decision request (DecisionRequest.scope.kind) the time-limited scope is written until; here (max_scope, and the scope of approvals and grants) it is called time_limited.

statusrequiredApprovalState

expired: nobody decided before it expired; counts as denied.

scoperequiredScopeKind | null

The scope given on approval; null in other states.

decided_viarequired"signature" | "api_key" | "console" | null

How the decision arrived - a signed callback from your backend, an API key, or a team member in the console.

created_atrequiredstring (date-time)
expires_atrequiredstring (date-time)
decided_atrequiredstring (date-time) | null

For expired requests, this is expires_at.

ApprovalDecisionStatus

FieldTypeDescription
statusrequired"approved" | "denied"
scopeScopeKind

Present only when approved.

ApprovalList

FieldTypeDescription
datarequiredarray of Approval
nextrequiredstring | null

ApprovalRequestedEvent

FieldTypeDescription
idrequiredstring
typerequired"approval.requested"
createdrequiredstring (date-time)
environment_idrequiredstring
datarequiredobject

ApprovalState

expired: nobody decided before it expired; counts as denied.

"pending" | "approved" | "denied" | "expired"

AttachAttachedMessage

The first message.

FieldTypeDescription
typerequired"attached"
processrequiredProcess

AttachClientMessage

Messages sent by the client on the attach WebSocket (JSON text); fields can be combined.

FieldTypeDescription
stdinstring
stdin_eofboolean
signalSignal

AttachErrorMessage

With next, the VM disconnected (the server then closes the connection; reconnect using next); without it, a message from the client could not be understood (the connection stays open).

FieldTypeDescription
typerequired"error"
messagerequiredstring
nextinteger (int64)

AttachExitMessage

The process exited; the server then closes the connection.

FieldTypeDescription
typerequired"exit"
exitrequiredProcessExit
nextrequiredinteger (int64)

AttachOutputMessage

FieldTypeDescription
typerequired"output"
streamrequired"stdout" | "stderr"
offsetrequiredinteger (int64)

Offset of the first byte of this chunk

datarequiredstring

Decoded as UTF-8

AttachServerMessage

Messages sent by the server on the attach WebSocket (one JSON text message each), distinguished by type.

AttachAttachedMessage | AttachOutputMessage | AttachExitMessage | AttachErrorMessage

AuditChain

FieldTypeDescription
chainrequiredstring
first_seqrequiredinteger

The first sequence number the control plane received (greater than 1 if earlier lines on the host were lost).

last_seqrequiredinteger
headrequiredstring

SHA-256 of the last line (the chain head).

broken_at_seqrequiredinteger | null

The chain no longer links up from this number on; null if intact.

updated_atrequiredstring (date-time)

AuditChainList

FieldTypeDescription
datarequiredarray of AuditChain
intactrequiredboolean

Every chain links up.

AuditRecord

FieldTypeDescription
chainrequiredstring

Which hash chain (one per VM).

seqrequiredinteger

Sequence number within the chain, starting at 1.

atrequiredstring (date-time)
sourcerequiredstring

Source, for example egress (outbound request), gateway (request made with a credential), browser (browser action); unknown if the record has none. Approval decisions are not separate records here: they appear on the record of the action they gated.

recordrequiredobject

The parsed raw line (with seq and prev); fields vary by source.

AuditRecordList

FieldTypeDescription
datarequiredarray of AuditRecord
nextrequiredstring | null

Opaque pagination position.

AuthorizeConnectionRequest

FieldTypeDescription
end_user_idrequiredstring
connectorsrequiredarray of Connector

Connectors of a single provider; unknown connectors, or a mix of two providers, give 400.

return_urlrequiredstring (uri)

The page of yours to return to after authorization; must be an absolute http(s) URL.

BatchCreateRequest

FieldTypeDescription
environmentsrequiredarray of CreateEnvironmentRequest

BatchCreateResponse

FieldTypeDescription
resultsrequiredarray of BatchCreateResult

BatchCreateResult

{environment} on success, {error, message} on failure (only errors of the 400 / 409 kind appear here).

object | Error

BrowserLease

FieldTypeDescription
idrequiredstring
environment_idrequiredstring
end_user_idrequiredstring
profile_idrequiredstring | null
moderequiredBrowserLeaseMode

write = load the signed-in state and save it on release (one at a time per profile); read = load only; clean = a clean browser.

profile_versionrequiredinteger (int64) | null

Signed-in state version loaded when the lease was granted

staterequiredBrowserLeaseState

releasing = a write lease released through the REST API is waiting for the host to send back the signed-in state (at most 60 seconds); it always ends up released.

save_outcomerequired"saved" | "discarded" | null

Whether the signed-in state was saved or discarded when the write lease ended; null for other leases and for leases not yet settled (active, releasing).

created_atrequiredstring (date-time)
renewed_atrequiredstring (date-time)
expires_atrequiredstring (date-time)
ended_atrequiredstring (date-time) | null
takeover_started_atrequiredstring (date-time) | null

If the end user is currently taking over (all of the Agent's browser commands are rejected), when the takeover began; null when not taken over.

BrowserLeaseList

FieldTypeDescription
datarequiredarray of BrowserLease
nextrequiredstring | null

BrowserLeaseMode

write = load the signed-in state and save it on release (one at a time per profile); read = load only; clean = a clean browser.

"write" | "read" | "clean"

BrowserLeaseState

releasing = a write lease released through the REST API is waiting for the host to send back the signed-in state (at most 60 seconds); it always ends up released.

"pending" | "active" | "releasing" | "released" | "expired" | "failed"

BrowserLimits

FieldTypeDescription
max_leases_per_developerrequiredinteger
max_leases_per_end_userrequiredinteger
lease_ttl_secsrequiredinteger

BrowserProfile

FieldTypeDescription
idrequiredstring
end_user_idrequiredstring
namerequiredstring
versionrequiredinteger (int64)

Signed-in state version; increases by 1 each time a write lease saves successfully

saved_atrequiredstring (date-time) | null
created_atrequiredstring (date-time)
updated_atrequiredstring (date-time)

BrowserProfileList

FieldTypeDescription
datarequiredarray of BrowserProfile
nextrequiredstring | null

BrowserTakeover

FieldTypeDescription
leaserequiredBrowserLease
view_urlrequiredstring

The viewer page for the end user to open; single use. Do not log it.

expires_atrequiredstring (date-time)

The URL expires after 10 minutes.

ChooseDeveloperError

FieldTypeDescription
errorrequired"choose_developer"
messagerequiredstring
developersrequiredarray of Team

ConfigEnv

Environment variables, at most 100 and 32 KiB in total. Names are letters, digits and _, not starting with a digit, up to 128 characters. The platform's proxy and certificate variables (HTTP_PROXY, HTTPS_PROXY, NO_PROXY, ALL_PROXY, SSL_CERT_FILE, SSL_CERT_DIR, REQUESTS_CA_BUNDLE, CURL_CA_BUNDLE, NODE_EXTRA_CA_CERTS, GIT_SSL_CAINFO, in any case), HOME, USER, LOGNAME and names starting with TEMPER_ are reserved. Values are up to 4096 bytes, without single quotes or control characters other than tab.

map of string

ConfigFile

FieldTypeDescription
contentrequiredstring
encoding"utf8" | "base64"

base64 for binary content.

ConfigFiles

Files by name, at most 20 and 256 KiB in total (decoded). Names are letters, digits, ., _ and -, not starting with . or -, up to 128 characters.

map of ConfigFile

Connection

One authorization by one end user at one provider. Never includes tokens.

FieldTypeDescription
idrequiredstring
end_user_idrequiredstring
providerrequiredOAuthProvider
connectorsrequiredarray of Connector
scopesrequiredarray of string

The OAuth scopes the provider actually granted.

accountrequiredstring | null

Account: the email address for Google, the team for Slack.

statusrequiredConnectionStatus

error: the provider rejected the token refresh (most likely the user revoked access at the provider); the user must authorize again.

errorrequiredstring | null

The reason for the most recent refresh failure.

access_expires_atrequiredstring (date-time) | null
refreshed_atrequiredstring (date-time) | null
created_atrequiredstring (date-time)
updated_atrequiredstring (date-time)
revoked_atrequiredstring (date-time) | null

ConnectionAuthorization

FieldTypeDescription
urlrequiredstring

The provider's consent page; send the end user there.

expires_atrequiredstring (date-time)

The link expires after 10 minutes.

ConnectionList

FieldTypeDescription
datarequiredarray of Connection
has_morerequiredboolean

More than 500 connections; the list is incomplete.

ConnectionStatus

error: the provider rejected the token refresh (most likely the user revoked access at the provider); the user must authorize again.

"active" | "revoked" | "error"

ConnectionWebhookEvent

FieldTypeDescription
idrequiredstring
typerequired"connection.created" | "connection.revoked" | "connection.error"
createdrequiredstring (date-time)
environment_idrequiredstring

Empty string for connection.created and connection.revoked; for connection.error, the environment that triggered the refresh.

datarequiredobject

connection.created: provider, connectors, account, replaced (the id of the old connection it replaced, or null); connection.revoked: provider; connection.error: error.

Connector

Built-in connectors: gmail, calendar (google), slack (slack).

"gmail" | "calendar" | "slack"

ConsoleSession

FieldTypeDescription
tokenrequiredstring

temper_cs_..., shown only this once.

expires_atrequiredstring (date-time)

Expires at this time if idle (pushed back on each use, up to 7 days after sign-in).

memberrequiredMember
developerrequiredobject
developersrequiredarray of Team

CreateBrowserProfileRequest

FieldTypeDescription
end_user_idrequiredstring
namerequiredstring

CreateConsoleSessionRequest

FieldTypeDescription
coderequiredstring
verifierrequiredstring

The PKCE verifier for the challenge sent at start.

developer_idstring | null

Which team to choose when the member belongs to several.

CreatedApiKey

FieldTypeDescription
idrequiredstring
namerequiredstring | null

Keys issued by the platform operator have no name.

prefixrequiredstring

The first few characters of the key (temper_sk_...), for identifying it.

created_atrequiredstring (date-time)
created_byrequiredstring | null

Who created it (member email; null for keys issued by the platform operator).

last_used_atrequiredstring (date-time) | null
revoked_atrequiredstring (date-time) | null
keyrequiredstring

temper_sk_..., shown only in this response.

CreateEnvironmentRequest

FieldTypeDescription
end_user_idrequiredstring

Your own id for the end user

agent_versionstring | null

If omitted, the developer's default version is used. Whether the version has been uploaded is not checked.

resourcesResourcesInput

All optional; defaults are 2 vCPUs, a 4096 MiB memory limit, 1024 MiB base memory and a 10 GiB disk.

idleIdleSettingsInput

Idle thresholds (seconds); 0 = this tier is never applied automatically, otherwise 60–7776000 (90 days). Both thresholds count from the last activity: by default an environment is suspended after 6 hours idle and stopped after 7 days idle, so keep stop_after_secs larger than suspend_after_secs. With suspension turned off (0) the environment is never stopped either.

envConfigEnv

Environment variables, at most 100 and 32 KiB in total. Names are letters, digits and _, not starting with a digit, up to 128 characters. The platform's proxy and certificate variables (HTTP_PROXY, HTTPS_PROXY, NO_PROXY, ALL_PROXY, SSL_CERT_FILE, SSL_CERT_DIR, REQUESTS_CA_BUNDLE, CURL_CA_BUNDLE, NODE_EXTRA_CA_CERTS, GIT_SSL_CAINFO, in any case), HOME, USER, LOGNAME and names starting with TEMPER_ are reserved. Values are up to 4096 bytes, without single quotes or control characters other than tab.

filesConfigFiles

Files by name, at most 20 and 256 KiB in total (decoded). Names are letters, digits, ., _ and -, not starting with . or -, up to 128 characters.

secretsmap of PutSecretRequest

Environment-level secrets by name (an environment can have at most 100; so can the developer level), created in the same transaction as the environment (same fields and rules as PUT /v1/environments/{id}/secrets/{name}). If any is invalid, nothing is created. Their placeholders exist before the VM first starts.

egress_allowarray of string

The environment's own egress allowlist (same as allow in PUT /v1/environments/{id}/egress). Omitted = use the developer-level list.

templatestring | null

Template version as name:version (see createTemplateVersion); it must be ready. Omitted or null = the platform's default runtime. An environment stays on its template version; changing it means moving the environment to a new VM, like an Agent upgrade.

CreateTemplateVersionRequest

FieldTypeDescription
fromstring | null

Base version as name:version (one of your own, and ready). Omitted or null = the platform's default runtime (Debian 13 with systemd).

stepsrequiredarray of TemplateStep

Build steps, run in order. All copy contents together are limited to 4 MiB (decoded).

startTemplateStart

The command environments with this template run when they have no Agent package: a string (run with /bin/sh -c) or an argv array, started in the last workdir. With an Agent package, the package's /opt/agent/bin/start runs instead. Without either, the environment simply waits for exec.

CreateWakeupRequest

FieldTypeDescription
atrequiredstring (date-time)

RFC 3339, from 1 minute ago to 366 days ahead

reasonstring

DecisionRequest

FieldTypeDescription
decisionrequired"approve" | "deny"
scopeGrantScopeRequest

Required when approving; ignored when denying.

DefaultPolicy

FieldTypeDescription
rulesrequiredarray of PolicyRule
updated_atrequiredstring (date-time) | null

Null if never set.

DefaultVersion

FieldTypeDescription
default_versionrequiredstring

DesiredState

Desired state (changed through the API).

"running" | "suspended" | "stopped" | "destroyed"

DirectoryEntry

FieldTypeDescription
namerequiredstring
typerequired"file" | "directory" | "symlink" | "other"

Symbolic links are not followed

sizerequiredinteger (int64)
modified_atrequiredstring (date-time) | null
moderequiredstring

Octal permission bits, for example 644, 755

DirectoryListing

FieldTypeDescription
pathrequiredstring

The path given in the request (unchanged)

entriesrequiredarray of DirectoryEntry
truncatedrequiredboolean

More than 10000 entries; the rest were cut off

EgressAllow

FieldTypeDescription
allowrequiredarray of string

Environment

FieldTypeDescription
idrequiredstring
end_user_idrequiredstring
agent_versionrequiredstring | null
templaterequiredstring | null

The template version the environment runs (name:version); null = the platform's default runtime.

resourcesrequiredResources

Resource specification.

desired_staterequiredDesiredState

Desired state (changed through the API).

staterequiredEnvironmentState

Actual state (reported back by the host).

idlerequiredIdleState
last_active_atrequiredstring (date-time)

The most recent activity (the VM using CPU, a wake, keep-awake, a scheduled wakeup). Idle tiers are measured from this time.

over_limitrequiredstring | null

Which monthly limit was exceeded (a human-readable reason, for example environment egress_gib 1.20 >= 1); null if none. An environment over its limit is suspended, and resume, wake and exec return 409 limit_exceeded until the limit is raised or deleted, or the next month begins (see setLimit).

created_atrequiredstring (date-time)
updated_atrequiredstring (date-time)

EnvironmentConfig

Non-secret configuration for an environment. Inside the runtime unit, env is written to /run/temper/env, which the Agent service, exec and login shells load (after the Agent package's own /opt/agent/env, so these values win); each file appears read-only at /run/temper/files/NAME. Put secret values in secrets instead (PUT /v1/environments/{id}/secrets/{name}).

FieldTypeDescription
envConfigEnv

Environment variables, at most 100 and 32 KiB in total. Names are letters, digits and _, not starting with a digit, up to 128 characters. The platform's proxy and certificate variables (HTTP_PROXY, HTTPS_PROXY, NO_PROXY, ALL_PROXY, SSL_CERT_FILE, SSL_CERT_DIR, REQUESTS_CA_BUNDLE, CURL_CA_BUNDLE, NODE_EXTRA_CA_CERTS, GIT_SSL_CAINFO, in any case), HOME, USER, LOGNAME and names starting with TEMPER_ are reserved. Values are up to 4096 bytes, without single quotes or control characters other than tab.

filesConfigFiles

Files by name, at most 20 and 256 KiB in total (decoded). Names are letters, digits, ., _ and -, not starting with . or -, up to 128 characters.

EnvironmentEgress

FieldTypeDescription
allowrequiredarray of string
inheritedrequiredboolean

true = the environment has no list of its own and uses the developer-level one.

EnvironmentEvent

FieldTypeDescription
idrequiredinteger (int64)

Increasing cursor (for pagination); shared across all environments, so not contiguous

kindrequiredstring

Event kind, for example created, desired_<state>, running, idle_suspend, keep_awake, agent_upgrade, agent_schedule_set, limit_exceeded, audit_chain_broken.

detailrequiredobject

Event details; fields vary by kind. Actions registered by the Agent itself carry source: agent.

atrequiredstring (date-time)

EnvironmentEventList

FieldTypeDescription
datarequiredarray of EnvironmentEvent
nextrequiredinteger (int64) | null

The after for the next page; null when this page is not full.

EnvironmentList

FieldTypeDescription
datarequiredarray of Environment
nextrequiredstring | null

EnvironmentPolicy

FieldTypeDescription
environment_idrequiredstring
sourcerequired"environment" | "developer" | "default"

Where the rules come from: the environment's own policy, the developer default, or the built-in behavior (empty rules).

rulesrequiredarray of PolicyRule

EnvironmentState

Actual state (reported back by the host).

"pending" | "running" | "suspended" | "stopped" | "destroyed" | "failed"

EnvironmentUsage

FieldTypeDescription
active_hoursrequirednumber
cpu_hoursrequirednumber
memory_gib_hoursrequirednumber
storage_gib_hoursrequirednumber
egress_gibrequirednumber
browser_hoursrequirednumber
environment_idrequiredstring
end_user_idrequiredstring

Error

FieldTypeDescription
errorrequiredstring

Machine-readable code: bad_request(400), unauthorized(401), forbidden(403), not_found(404), method_not_allowed(405), payload_too_large(413), unsupported_media_type(415), invalid_body(422), internal(500); 409: environment_exists, idempotency_key_reused, invalid_state_transition, environment_destroyed, environment_failed, version_exists, template_not_ready, template_in_use, template_building, rollout_in_progress, not_latest_rollout, profile_exists, profile_in_use, profile_locked, lease_not_active, no_oauth_client, already_decided, limit_exceeded, export_too_large, not_taken_over, member_exists, last_owner, choose_developer; 403: session_required, reauth_required; 400: invalid_code; 429: rate_limited; 503: login_unavailable; approval decisions additionally use 400 invalid_decision / missing_scope / invalid_scope, 401 invalid_signature, 403 scope_too_wide; 429: wakeup_limit_reached, lease_limit_reached, too_many_processes; 503: host_unavailable, guest_unavailable, environment_not_placed, environment_not_running, exec_failed, exec_timeout, file_operation_failed, provider_error (the OAuth provider returned an error). Other status codes for requests rejected before reaching the endpoint are reported as http_error.

messagerequiredstring
environment_idstring

With environment_exists and idempotency_key_reused, the id of the existing environment.

ExecRequest

Provide exactly one of argv and command, and it must not be empty; strings must not contain NUL.

FieldTypeDescription
argvarray of string

Executed as is, for example ["python3", "-c", "print(1)"].

commandstring

Run with bash -lc, for example ls -la | head.

envmap of string

Extra environment variables. Names consist of letters, digits and underscores and do not start with a digit; variables already set in agent.env or the Agent package's env cannot be overridden.

cwdstring

Working directory (a path inside the runtime unit); defaults to the agent user's home directory.

timeout_secsinteger
stdinstring

Standard input for the process (closed afterwards); if omitted, stdin is /dev/null.

ExecResult

FieldTypeDescription
exit_coderequiredinteger | null

Exit code on normal exit; null if killed by a signal

signalrequiredinteger | null

The signal that killed the process (signal number)

timed_outrequiredboolean

Killed for exceeding timeout_secs

stdoutrequiredstring

At most 1 MiB, decoded as UTF-8

stderrrequiredstring
stdout_truncatedrequiredboolean
stderr_truncatedrequiredboolean
duration_msrequiredinteger (int64)

Measured from when the control plane received the request (including waking and connecting)

Grant

FieldTypeDescription
idrequiredstring
environment_idrequiredstring
connectorrequiredstring
categoryrequiredActionCategory

Action category. send, pay, delete and change_permission are high-risk categories that rules cannot allow; they always require approval.

scoperequired"task" | "session" | "time_limited" | "permanent"

The scope the grant covers ("once" leaves no grant).

scope_idrequiredstring | null

The task / session id.

untilrequiredstring (date-time) | null

Expiry time for time_limited.

approval_idrequiredstring | null
created_atrequiredstring (date-time)

GrantList

FieldTypeDescription
datarequiredarray of Grant

GrantScopeRequest

Grant scope. The task / session id must match the approval request's own task_id / session_id; until takes a future time in unix seconds (it is called until here and time_limited in stored grants).

object | object | object | object | object

IdlePatch

FieldTypeDescription
suspend_after_secsIdleSecs

0 or 60–7776000.

stop_after_secsIdleSecs

0 or 60–7776000.

IdleSecs

0 or 60–7776000.

integer

IdleSettingsInput

Idle thresholds (seconds); 0 = this tier is never applied automatically, otherwise 60–7776000 (90 days). Both thresholds count from the last activity: by default an environment is suspended after 6 hours idle and stopped after 7 days idle, so keep stop_after_secs larger than suspend_after_secs. With suspension turned off (0) the environment is never stopped either.

FieldTypeDescription
suspend_after_secsIdleSecs

0 or 60–7776000.

stop_after_secsIdleSecs

0 or 60–7776000.

IdleState

FieldTypeDescription
suspend_after_secsrequiredinteger
stop_after_secsrequiredinteger
keep_awake_untilrequiredstring (date-time) | null

Until this time the environment will not be suspended by the idle tiers.

KeepAwakeRequest

FieldTypeDescription
secondsrequiredinteger

Me

FieldTypeDescription
developerrequiredobject
memberrequiredMember | null

Null when using an API key.

authrequired"session" | "api_key"
developersarray of Team

Present only with a session: every team this account can access.

Member

FieldTypeDescription
idrequiredstring
emailrequiredstring

Lowercase.

namerequiredstring | null
rolerequiredMemberRole

owner: manages members, API keys and the webhook, plus everything a member can do; member: day-to-day operations.

created_atrequiredstring (date-time)

MemberList

FieldTypeDescription
datarequiredarray of Member

MemberRole

owner: manages members, API keys and the webhook, plus everything a member can do; member: day-to-day operations.

"owner" | "member"

OAuthClient

FieldTypeDescription
providerrequiredOAuthProvider
client_idrequiredstring | null

Registered by you; null if not registered.

updated_atrequiredstring (date-time) | null
platform_app_availablerequiredboolean

Whether the platform test app is configured (used when you have not registered your own app).

redirect_urirequiredstring

OAuthClientList

FieldTypeDescription
datarequiredarray of OAuthClient

OAuthClientRegistered

FieldTypeDescription
providerrequiredOAuthProvider
client_idrequiredstring
redirect_urirequiredstring

The callback URL to register with the provider.

OAuthProvider

"google" | "slack"

OutputChunk

FieldTypeDescription
streamrequired"stdout" | "stderr"
offsetrequiredinteger (int64)

Offset of the first byte of this chunk

datarequiredstring

Decoded as UTF-8 (invalid bytes replaced with U+FFFD)

Package

FieldTypeDescription
versionrequiredstring
sha256requiredstring
size_bytesrequiredinteger (int64)
created_atrequiredstring (date-time)

PackageList

FieldTypeDescription
datarequiredarray of Package
default_versionrequiredstring | null

PolicyCheckRequest

FieldTypeDescription
connectorrequiredstring

A built-in connector (gmail, calendar, slack, browser) or secret:NAME for a developer secret.

categoryrequiredActionCategory

Action category. send, pay, delete and change_permission are high-risk categories that rules cannot allow; they always require approval.

task_idstring

Task-scoped grants apply only when this matches.

session_idstring

Session-scoped grants apply only when this matches.

PolicyCheckResult

FieldTypeDescription
decisionrequired"allow" | "ask" | "deny"
reasonrequired"rule" | "grant" | "deny_rule" | "ask_rule" | "high_risk" | "no_rule" | "infrastructure_credential"

rule: an allow rule matched. grant: an existing grant covers it (grant_id). deny_rule: a deny rule matched (deny wins over everything). ask_rule: an ask rule matched (ask wins over allow). high_risk: no ask rule, but send / pay / delete / change_permission always need approval. no_rule: nothing matched, so it is denied. infrastructure_credential: the connector is an infrastructure secret, which skips the action policy.

max_scopeScopeKind

Grant scope, from narrowest to widest: once < task < session < time_limited < permanent. Note: in a decision request (DecisionRequest.scope.kind) the time-limited scope is written until; here (max_scope, and the scope of approvals and grants) it is called time_limited.

grant_idstring
matched_rulesrequiredarray of integer

Indexes (from 0) of the rules in the effective policy that match this connector and category.

sourcerequired"environment" | "developer" | "default"

Where the effective rules come from.

PolicyRule

A single rule. Omitting connector or category matches any value. When several rules match, deny > ask > allow. When no rule matches, the built-in behavior applies: high-risk categories require approval (max_scope is permanent) and everything else is denied.

FieldTypeDescription
connectorstring

Connector (credential id), for example gmail, calendar, slack, or secret:<NAME> for requests made with a developer secret. A trailing * matches by prefix: secret:* covers every developer secret.

categoryActionCategory

Action category. send, pay, delete and change_permission are high-risk categories that rules cannot allow; they always require approval.

effectrequired"allow" | "deny" | "ask"
max_scopeScopeKind

Only allowed on ask: the widest grant the end user can give. Defaults to permanent.

Process

FieldTypeDescription
idrequiredstring
argvrequiredarray of string

The argv actually executed (command is turned into /bin/bash -lc ...)

started_atrequiredinteger (int64)

Start time (Unix seconds, not RFC 3339)

runningrequiredboolean
exitProcessExit

Present only once the process has exited

output_bytesrequiredinteger (int64)

Total bytes output so far (stdout and stderr combined); continue reading from here next time

output_startrequiredinteger (int64)

Offset of the oldest byte still retained in the VM (anything earlier has been dropped)

stdin_openrequiredboolean

stdin can still be written

ProcessExit

FieldTypeDescription
coderequiredinteger | null

Exit code on normal exit; null if killed by a signal

signalinteger

The signal that killed the process (signal number); the field is absent otherwise

timed_outrequiredboolean

ProcessList

FieldTypeDescription
datarequiredarray of Process

ProcessOutput

FieldTypeDescription
processrequiredProcess

The process state when output reading began

chunksrequiredarray of OutputChunk
nextrequiredinteger (int64)

The since for the next call

exitedrequiredboolean

The process was seen to exit during this read

exitrequiredProcessExit | null

PutEgressRequest

FieldTypeDescription
allowrequiredarray of string | null

An exact domain or *.example.com. For an environment, null reverts to the developer-level list; for the developer level, null clears the list.

PutPolicyRequest

400 cases: allow for a high-risk category, max_scope on anything other than ask, more than 100 rules, or a connector that is empty or longer than 100 characters. Unknown fields, or a wrong type or enum value, give 422 invalid_body.

FieldTypeDescription
rulesrequiredarray of PolicyRule

PutSecretRequest

FieldTypeDescription
valuerequiredstring

The real value, at most 8192 bytes, with no newlines. Never returned by any endpoint afterwards.

hostsrequiredarray of string

The value is sent only to these exact domains (lowercase, without scheme, port or wildcards).

pathsarray of string

Allowlist of path prefixes (starting with /); omitted or empty = no restriction.

headerstring

The request header that receives the real value, default authorization. Cannot be host, cookie or content-length.

prefixstring

Header value = prefix + real value. Defaults to Bearer when header is authorization, and to empty for custom headers. No newlines.

kindSecretKind

standard: a key the Agent uses on the end user's behalf. Requests that use it go through the action policy as connector secret:NAME (GET/HEAD/OPTIONS count as read, other methods as write). infrastructure: your own infrastructure credential, for example the token your Agent uses to connect back to your backend. It is still sent only to hosts and paths and every use is audited, but requests that use it skip the action policy. A request that also carries a standard or built-in credential is judged by that credential.

ReleaseBrowserLeaseRequest

FieldTypeDescription
saveboolean | null

Whether a write lease saves the signed-in state; omitted or null means true. Only meaningful for write leases.

Resources

Resource specification.

FieldTypeDescription
cpusrequiredinteger
memory_mibrequiredinteger

Memory limit

base_memory_mibrequiredinteger

Base memory, no more than memory_mib

disk_gibrequiredinteger

ResourcesInput

All optional; defaults are 2 vCPUs, a 4096 MiB memory limit, 1024 MiB base memory and a 10 GiB disk.

FieldTypeDescription
cpusinteger
memory_mibinteger
base_memory_mibinteger

256 to memory_mib

disk_gibinteger

Rollout

FieldTypeDescription
idrequiredstring
versionrequiredstring
percentrequiredinteger
batch_sizerequiredinteger
max_failuresrequiredinteger
staterequiredRolloutState
reasonrequiredstring | null

Why it was rolled back (for an automatic rollback, the failed environments and errors; for a manual one, manual)

created_atrequiredstring (date-time)
updated_atrequiredstring (date-time)
finished_atrequiredstring (date-time) | null

RolloutDetail

FieldTypeDescription
idrequiredstring
versionrequiredstring
percentrequiredinteger
batch_sizerequiredinteger
max_failuresrequiredinteger
staterequiredRolloutState
reasonrequiredstring | null

Why it was rolled back (for an automatic rollback, the failed environments and errors; for a manual one, manual)

created_atrequiredstring (date-time)
updated_atrequiredstring (date-time)
finished_atrequiredstring (date-time) | null
environmentsrequiredarray of RolloutMember

RolloutList

FieldTypeDescription
datarequiredarray of Rollout

RolloutMember

An environment whose version was changed by the rollout.

FieldTypeDescription
environment_idrequiredstring
from_versionrequiredstring | null

The original version (restored on rollback)

upgraded_atrequiredstring (date-time)
deferredrequiredboolean

Not running when switched, so only the version was changed (effective at next start) without waiting for it to become healthy

healthy_atrequiredstring (date-time) | null
failed_atrequiredstring (date-time) | null

Entered failed, or was not healthy within 10 minutes

errorrequiredstring | null
rolled_back_atrequiredstring (date-time) | null

RolloutState

"active" | "paused" | "completed" | "rolled_back"

Schedule

Either a recurring rule (cron + time zone) or a one-time rule (at); exactly one of the two.

FieldTypeDescription
idrequiredstring
sourcerequired"agent" | "developer"
keyrequiredstring

Name chosen by the registrant; the same key overwrites

cronrequiredstring | null

Standard 5 fields (minute hour day month weekday)

tzrequiredstring | null

IANA time zone; present together with cron

atrequiredstring (date-time) | null
next_atrequiredstring (date-time) | null

Next occurrence (computed by the control plane)

last_fired_atrequiredstring (date-time) | null
created_atrequiredstring (date-time)
updated_atrequiredstring (date-time)

ScheduleList

FieldTypeDescription
datarequiredarray of Schedule

ScopeKind

Grant scope, from narrowest to widest: once < task < session < time_limited < permanent. Note: in a decision request (DecisionRequest.scope.kind) the time-limited scope is written until; here (max_scope, and the scope of approvals and grants) it is called time_limited.

"once" | "task" | "session" | "time_limited" | "permanent"

Secret

A secret (without its value).

FieldTypeDescription
namerequiredstring
environment_idrequiredstring | null

Set only for environment-level secrets; null for developer-level ones.

hostsrequiredarray of string
pathsrequiredarray of string
headerrequiredstring
prefixrequiredstring
kindrequiredSecretKind

standard: a key the Agent uses on the end user's behalf. Requests that use it go through the action policy as connector secret:NAME (GET/HEAD/OPTIONS count as read, other methods as write). infrastructure: your own infrastructure credential, for example the token your Agent uses to connect back to your backend. It is still sent only to hosts and paths and every use is audited, but requests that use it skip the action policy. A request that also carries a standard or built-in credential is judged by that credential.

created_atrequiredstring (date-time)
updated_atrequiredstring (date-time)
last_used_atrequiredstring (date-time) | null

The last time the credential gateway substituted this value.

SecretKind

standard: a key the Agent uses on the end user's behalf. Requests that use it go through the action policy as connector secret:NAME (GET/HEAD/OPTIONS count as read, other methods as write). infrastructure: your own infrastructure credential, for example the token your Agent uses to connect back to your backend. It is still sent only to hosts and paths and every use is audited, but requests that use it skip the action policy. A request that also carries a standard or built-in credential is judged by that credential.

"standard" | "infrastructure"

SecretList

FieldTypeDescription
datarequiredarray of Secret

SetDefaultVersionRequest

FieldTypeDescription
versionrequiredstring

SetLimitRequest

FieldTypeDescription
environment_idstring | null

Omit for developer-level.

metricrequiredUsageMetric

active_hours: hours the VM was running; cpu_hours: CPU time (hours); memory_gib_hours: VMM memory GiB × hours; storage_gib_hours: actual data disk usage GiB × hours; egress_gib: egress traffic in GiB; browser_hours: browser lease hours.

monthly_limitrequirednumber

SetLimitResponse

FieldTypeDescription
environment_idrequiredstring | null
metricrequiredUsageMetric

active_hours: hours the VM was running; cpu_hours: CPU time (hours); memory_gib_hours: VMM memory GiB × hours; storage_gib_hours: actual data disk usage GiB × hours; egress_gib: egress traffic in GiB; browser_hours: browser lease hours.

monthly_limitrequirednumber

SetOAuthClientRequest

FieldTypeDescription
client_idrequiredstring
client_secretrequiredstring

SetWebhookRequest

FieldTypeDescription
urlrequiredstring (uri)
rotate_secretboolean

SetWebhookResponse

FieldTypeDescription
urlrequiredstring
secretrequiredstring | null

The new whsec_... (shown only this once); null if the secret was not rotated.

Signal

"TERM" | "KILL" | "INT" | "HUP"

SignalRequest

FieldTypeDescription
signalrequiredSignal

SpawnRequest

Same as ExecRequest; see each field for the differences.

FieldTypeDescription
argvarray of string
commandstring
envmap of string
cwdstring
timeout_secsinteger

Maximum run time, after which the process is killed; 0 = no limit

stdinboolean

You will write stdin later through attach; otherwise stdin is /dev/null

StartRolloutRequest

FieldTypeDescription
versionrequiredstring
percentrequiredinteger
batch_sizeinteger

Number of environments switched at the same time per batch

max_failuresinteger

Roll back automatically when failures exceed this number

TakeoverRequestedEvent

FieldTypeDescription
idrequiredstring
typerequired"browser.takeover_requested"
createdrequiredstring (date-time)
environment_idrequiredstring
datarequiredobject

Team

FieldTypeDescription
idrequiredstring

Developer id.

namerequiredstring
rolerequiredMemberRole

owner: manages members, API keys and the webhook, plus everything a member can do; member: day-to-day operations.

TemplateCopy

Writes one file into the template.

FieldTypeDescription
pathrequiredstring

Absolute file path (no .., not ending in /); parent directories are created.

contentrequiredstring
encoding"utf8" | "base64"

base64 for binary content.

modestring | null

Octal permissions, default 0644.

TemplateList

FieldTypeDescription
datarequiredarray of object

TemplateStart

The command environments with this template run when they have no Agent package: a string (run with /bin/sh -c) or an argv array, started in the last workdir. With an Agent package, the package's /opt/agent/bin/start runs instead. Without either, the environment simply waits for exec.

string | array of string | null

TemplateState

building until the build finishes, then ready (environments can use it) or failed (see error and log).

"building" | "ready" | "failed"

TemplateStep

One build step, an object with exactly one key.

object | object | object | object

TemplateVersion

FieldTypeDescription
namerequiredstring
versionrequiredstring
fromrequiredstring | null

The base version (name:version); null = the platform's default runtime.

staterequiredTemplateState

building until the build finishes, then ready (environments can use it) or failed (see error and log).

errorrequiredstring | null

Why the build failed.

layer_countrequiredinteger

Layers on top of the default runtime, including the base version's; 0 until the version is ready.

startrequiredTemplateStart

The command environments with this template run when they have no Agent package: a string (run with /bin/sh -c) or an argv array, started in the last workdir. With an Agent package, the package's /opt/agent/bin/start runs instead. Without either, the environment simply waits for exec.

logrequiredstring

The last 64 KiB of the build log: each step's command and its output.

created_atrequiredstring (date-time)
finished_atrequiredstring (date-time) | null

TemplateVersionSummary

FieldTypeDescription
versionrequiredstring
staterequiredTemplateState

building until the build finishes, then ready (environments can use it) or failed (see error and log).

fromrequiredstring | null
created_atrequiredstring (date-time)

Usage

FieldTypeDescription
fromrequiredstring (date-time)
torequiredstring (date-time)
totalrequiredUsageTotals
datarequiredarray of EnvironmentUsage

UsageLimit

FieldTypeDescription
environment_idrequiredstring | null

null means developer-level (the total across all environments).

metricrequiredUsageMetric

active_hours: hours the VM was running; cpu_hours: CPU time (hours); memory_gib_hours: VMM memory GiB × hours; storage_gib_hours: actual data disk usage GiB × hours; egress_gib: egress traffic in GiB; browser_hours: browser lease hours.

monthly_limitrequirednumber
usedrequirednumber

Used this month (UTC).

updated_atrequiredstring (date-time)

UsageLimitList

FieldTypeDescription
datarequiredarray of UsageLimit

UsageMetric

active_hours: hours the VM was running; cpu_hours: CPU time (hours); memory_gib_hours: VMM memory GiB × hours; storage_gib_hours: actual data disk usage GiB × hours; egress_gib: egress traffic in GiB; browser_hours: browser lease hours.

"active_hours" | "cpu_hours" | "memory_gib_hours" | "storage_gib_hours" | "egress_gib" | "browser_hours"

UsageTotals

FieldTypeDescription
active_hoursrequirednumber
cpu_hoursrequirednumber
memory_gib_hoursrequirednumber
storage_gib_hoursrequirednumber
egress_gibrequirednumber
browser_hoursrequirednumber

Wakeup

FieldTypeDescription
idrequiredstring
atrequiredstring (date-time)
reasonrequiredstring
created_atrequiredstring (date-time)

WakeupList

FieldTypeDescription
datarequiredarray of Wakeup

Webhook

FieldTypeDescription
urlrequiredstring | null
secret_rotated_atrequiredstring (date-time) | null
previous_secret_expires_atrequiredstring (date-time) | null

When the old secret expires after a rotation; null if there is no old secret still valid.

WebhookEvent

FieldTypeDescription
idrequiredstring
typerequired"environment.agent_schedule_set" | "environment.agent_schedule_deleted" | "environment.agent_keep_awake" | "environment.agent_keep_awake_released" | "environment.agent_request_rejected" | "environment.limit_exceeded"

environment.<event>.

createdrequiredstring (date-time)
environment_idrequiredstring
datarequiredobject

Event details; fields vary by event. Agent-related events carry source: agent; environment.limit_exceeded is {reason}.

WidenRolloutRequest

FieldTypeDescription
percentrequiredinteger

Not lower than the current percentage

WriteFileResult

FieldTypeDescription
pathrequiredstring

The path given in the request (unchanged)

sizerequiredinteger (int64)

Number of bytes written