API reference
Schemas
Every object the API sends or accepts, as defined in the OpenAPI spec.
AcquireBrowserLeaseRequest
| Field | Type | Description |
|---|---|---|
environment_idrequired | string | |
profile_id | string | null | Omit for a clean browser |
mode | BrowserLeaseMode | null | With a profile, defaults to write and cannot be clean; without a profile, it can only be clean (or omitted). |
ActionCategory
Action category. send, pay, delete and change_permission are high-risk categories that rules cannot allow; they always require approval.
"read" | "write" | "send" | "pay" | "delete" | "change_permission"
AddMemberRequest
| Field | Type | Description |
|---|---|---|
emailrequired | string | |
rolerequired | MemberRole |
|
name | string | null |
AgentSettings
Defaults: on, 20 schedules, minimum interval 900 seconds, 7200 seconds per keep-awake, 21600 seconds of keep-awake per 24 hours.
| Field | Type | Description |
|---|---|---|
schedulingrequired | boolean | |
max_schedulesrequired | integer | |
min_interval_secsrequired | integer | |
keep_awake_max_secsrequired | integer | |
keep_awake_daily_secsrequired | integer |
AgentSettingsPatch
| Field | Type | Description |
|---|---|---|
scheduling | boolean | false = the Agent cannot register schedules or keep-awake |
max_schedules | integer | |
min_interval_secs | integer | |
keep_awake_max_secs | integer | |
keep_awake_daily_secs | integer |
ApiKey
| Field | Type | Description |
|---|---|---|
idrequired | string | |
namerequired | string | null | Keys issued by the platform operator have no name. |
prefixrequired | string | The first few characters of the key ( |
created_atrequired | string (date-time) | |
created_byrequired | string | null | Who created it (member email; null for keys issued by the platform operator). |
last_used_atrequired | string (date-time) | null | |
revoked_atrequired | string (date-time) | null |
ApiKeyList
| Field | Type | Description |
|---|---|---|
datarequired | array of ApiKey |
Approval
| Field | Type | Description |
|---|---|---|
idrequired | string | |
environment_idrequired | string | |
connectorrequired | string | |
categoryrequired | ActionCategory | Action category. |
summaryrequired | string | A one-sentence summary shown to the end user. |
session_idrequired | string | null | |
task_idrequired | string | null | |
max_scoperequired | ScopeKind | Grant scope, from narrowest to widest: |
statusrequired | ApprovalState |
|
scoperequired | ScopeKind | null | The scope given on approval; null in other states. |
decided_viarequired | "signature" | "api_key" | "console" | null | How the decision arrived - a signed callback from your backend, an API key, or a team member in the console. |
created_atrequired | string (date-time) | |
expires_atrequired | string (date-time) | |
decided_atrequired | string (date-time) | null | For expired requests, this is |
ApprovalDecisionStatus
| Field | Type | Description |
|---|---|---|
statusrequired | "approved" | "denied" | |
scope | ScopeKind | Present only when approved. |
ApprovalList
| Field | Type | Description |
|---|---|---|
datarequired | array of Approval | |
nextrequired | string | null |
ApprovalRequestedEvent
| Field | Type | Description |
|---|---|---|
idrequired | string | |
typerequired | "approval.requested" | |
createdrequired | string (date-time) | |
environment_idrequired | string | |
datarequired | object |
ApprovalState
expired: nobody decided before it expired; counts as denied.
"pending" | "approved" | "denied" | "expired"
AttachAttachedMessage
The first message.
| Field | Type | Description |
|---|---|---|
typerequired | "attached" | |
processrequired | Process |
AttachClientMessage
Messages sent by the client on the attach WebSocket (JSON text); fields can be combined.
| Field | Type | Description |
|---|---|---|
stdin | string | |
stdin_eof | boolean | |
signal | Signal |
AttachErrorMessage
With next, the VM disconnected (the server then closes the connection; reconnect using next); without it, a message from the client could not be understood (the connection stays open).
| Field | Type | Description |
|---|---|---|
typerequired | "error" | |
messagerequired | string | |
next | integer (int64) |
AttachExitMessage
The process exited; the server then closes the connection.
| Field | Type | Description |
|---|---|---|
typerequired | "exit" | |
exitrequired | ProcessExit | |
nextrequired | integer (int64) |
AttachOutputMessage
| Field | Type | Description |
|---|---|---|
typerequired | "output" | |
streamrequired | "stdout" | "stderr" | |
offsetrequired | integer (int64) | Offset of the first byte of this chunk |
datarequired | string | Decoded as UTF-8 |
AttachServerMessage
Messages sent by the server on the attach WebSocket (one JSON text message each), distinguished by type.
AttachAttachedMessage | AttachOutputMessage | AttachExitMessage | AttachErrorMessage
AuditChain
| Field | Type | Description |
|---|---|---|
chainrequired | string | |
first_seqrequired | integer | The first sequence number the control plane received (greater than 1 if earlier lines on the host were lost). |
last_seqrequired | integer | |
headrequired | string | SHA-256 of the last line (the chain head). |
broken_at_seqrequired | integer | null | The chain no longer links up from this number on; null if intact. |
updated_atrequired | string (date-time) |
AuditChainList
| Field | Type | Description |
|---|---|---|
datarequired | array of AuditChain | |
intactrequired | boolean | Every chain links up. |
AuditRecord
| Field | Type | Description |
|---|---|---|
chainrequired | string | Which hash chain (one per VM). |
seqrequired | integer | Sequence number within the chain, starting at 1. |
atrequired | string (date-time) | |
sourcerequired | string | Source, for example |
recordrequired | object | The parsed raw line (with |
AuditRecordList
| Field | Type | Description |
|---|---|---|
datarequired | array of AuditRecord | |
nextrequired | string | null | Opaque pagination position. |
AuthorizeConnectionRequest
| Field | Type | Description |
|---|---|---|
end_user_idrequired | string | |
connectorsrequired | array of Connector | Connectors of a single provider; unknown connectors, or a mix of two providers, give 400. |
return_urlrequired | string (uri) | The page of yours to return to after authorization; must be an absolute http(s) URL. |
BatchCreateRequest
| Field | Type | Description |
|---|---|---|
environmentsrequired | array of CreateEnvironmentRequest |
BatchCreateResponse
| Field | Type | Description |
|---|---|---|
resultsrequired | array of BatchCreateResult |
BatchCreateResult
{environment} on success, {error, message} on failure (only errors of the 400 / 409 kind appear here).
object | Error
BrowserLease
| Field | Type | Description |
|---|---|---|
idrequired | string | |
environment_idrequired | string | |
end_user_idrequired | string | |
profile_idrequired | string | null | |
moderequired | BrowserLeaseMode | write = load the signed-in state and save it on release (one at a time per profile); read = load only; clean = a clean browser. |
profile_versionrequired | integer (int64) | null | Signed-in state version loaded when the lease was granted |
staterequired | BrowserLeaseState |
|
save_outcomerequired | "saved" | "discarded" | null | Whether the signed-in state was saved or discarded when the write lease ended; null for other leases and for leases not yet settled (active, releasing). |
created_atrequired | string (date-time) | |
renewed_atrequired | string (date-time) | |
expires_atrequired | string (date-time) | |
ended_atrequired | string (date-time) | null | |
takeover_started_atrequired | string (date-time) | null | If the end user is currently taking over (all of the Agent's browser commands are rejected), when the takeover began; null when not taken over. |
BrowserLeaseList
| Field | Type | Description |
|---|---|---|
datarequired | array of BrowserLease | |
nextrequired | string | null |
BrowserLeaseMode
write = load the signed-in state and save it on release (one at a time per profile); read = load only; clean = a clean browser.
"write" | "read" | "clean"
BrowserLeaseState
releasing = a write lease released through the REST API is waiting for the host to send back the signed-in state (at most 60 seconds); it always ends up released.
"pending" | "active" | "releasing" | "released" | "expired" | "failed"
BrowserLimits
| Field | Type | Description |
|---|---|---|
max_leases_per_developerrequired | integer | |
max_leases_per_end_userrequired | integer | |
lease_ttl_secsrequired | integer |
BrowserProfile
| Field | Type | Description |
|---|---|---|
idrequired | string | |
end_user_idrequired | string | |
namerequired | string | |
versionrequired | integer (int64) | Signed-in state version; increases by 1 each time a write lease saves successfully |
saved_atrequired | string (date-time) | null | |
created_atrequired | string (date-time) | |
updated_atrequired | string (date-time) |
BrowserProfileList
| Field | Type | Description |
|---|---|---|
datarequired | array of BrowserProfile | |
nextrequired | string | null |
BrowserTakeover
| Field | Type | Description |
|---|---|---|
leaserequired | BrowserLease | |
view_urlrequired | string | The viewer page for the end user to open; single use. Do not log it. |
expires_atrequired | string (date-time) | The URL expires after 10 minutes. |
ChooseDeveloperError
| Field | Type | Description |
|---|---|---|
errorrequired | "choose_developer" | |
messagerequired | string | |
developersrequired | array of Team |
ConfigEnv
Environment variables, at most 100 and 32 KiB in total. Names are letters, digits and _, not starting with a digit, up to 128 characters.
The platform's proxy and certificate variables (HTTP_PROXY, HTTPS_PROXY, NO_PROXY, ALL_PROXY, SSL_CERT_FILE, SSL_CERT_DIR, REQUESTS_CA_BUNDLE, CURL_CA_BUNDLE, NODE_EXTRA_CA_CERTS, GIT_SSL_CAINFO, in any case),
HOME, USER, LOGNAME and names starting with TEMPER_ are reserved. Values are up to 4096 bytes, without single quotes or control characters other than tab.
map of string
ConfigFile
| Field | Type | Description |
|---|---|---|
contentrequired | string | |
encoding | "utf8" | "base64" |
|
ConfigFiles
Files by name, at most 20 and 256 KiB in total (decoded). Names are letters, digits, ., _ and -, not starting with . or -, up to 128 characters.
map of ConfigFile
Connection
One authorization by one end user at one provider. Never includes tokens.
| Field | Type | Description |
|---|---|---|
idrequired | string | |
end_user_idrequired | string | |
providerrequired | OAuthProvider | |
connectorsrequired | array of Connector | |
scopesrequired | array of string | The OAuth scopes the provider actually granted. |
accountrequired | string | null | Account: the email address for Google, the team for Slack. |
statusrequired | ConnectionStatus |
|
errorrequired | string | null | The reason for the most recent refresh failure. |
access_expires_atrequired | string (date-time) | null | |
refreshed_atrequired | string (date-time) | null | |
created_atrequired | string (date-time) | |
updated_atrequired | string (date-time) | |
revoked_atrequired | string (date-time) | null |
ConnectionAuthorization
| Field | Type | Description |
|---|---|---|
urlrequired | string | The provider's consent page; send the end user there. |
expires_atrequired | string (date-time) | The link expires after 10 minutes. |
ConnectionList
| Field | Type | Description |
|---|---|---|
datarequired | array of Connection | |
has_morerequired | boolean | More than 500 connections; the list is incomplete. |
ConnectionStatus
error: the provider rejected the token refresh (most likely the user revoked access at the provider); the user must authorize again.
"active" | "revoked" | "error"
ConnectionWebhookEvent
| Field | Type | Description |
|---|---|---|
idrequired | string | |
typerequired | "connection.created" | "connection.revoked" | "connection.error" | |
createdrequired | string (date-time) | |
environment_idrequired | string | Empty string for |
datarequired | object |
|
Connector
Built-in connectors: gmail, calendar (google), slack (slack).
"gmail" | "calendar" | "slack"
ConsoleSession
CreateBrowserProfileRequest
| Field | Type | Description |
|---|---|---|
end_user_idrequired | string | |
namerequired | string |
CreateConsoleSessionRequest
| Field | Type | Description |
|---|---|---|
coderequired | string | |
verifierrequired | string | The PKCE verifier for the challenge sent at start. |
developer_id | string | null | Which team to choose when the member belongs to several. |
CreatedApiKey
| Field | Type | Description |
|---|---|---|
idrequired | string | |
namerequired | string | null | Keys issued by the platform operator have no name. |
prefixrequired | string | The first few characters of the key ( |
created_atrequired | string (date-time) | |
created_byrequired | string | null | Who created it (member email; null for keys issued by the platform operator). |
last_used_atrequired | string (date-time) | null | |
revoked_atrequired | string (date-time) | null | |
keyrequired | string |
|
CreateEnvironmentRequest
| Field | Type | Description |
|---|---|---|
end_user_idrequired | string | Your own id for the end user |
agent_version | string | null | If omitted, the developer's default version is used. Whether the version has been uploaded is not checked. |
resources | ResourcesInput | All optional; defaults are 2 vCPUs, a 4096 MiB memory limit, 1024 MiB base memory and a 10 GiB disk. |
idle | IdleSettingsInput | Idle thresholds (seconds); 0 = this tier is never applied automatically, otherwise 60–7776000 (90 days). Both thresholds count from the last activity: by default an environment is suspended after 6 hours idle and stopped after 7 days idle, so keep |
env | ConfigEnv | Environment variables, at most 100 and 32 KiB in total. Names are letters, digits and |
files | ConfigFiles | Files by name, at most 20 and 256 KiB in total (decoded). Names are letters, digits, |
secrets | map of PutSecretRequest | Environment-level secrets by name (an environment can have at most 100; so can the developer level), created in the same transaction as the environment (same fields and rules as |
egress_allow | array of string | The environment's own egress allowlist (same as |
template | string | null | Template version as |
CreateTemplateVersionRequest
| Field | Type | Description |
|---|---|---|
from | string | null | Base version as |
stepsrequired | array of TemplateStep | Build steps, run in order. All |
start | TemplateStart | The command environments with this template run when they have no Agent package: a string (run with |
CreateWakeupRequest
| Field | Type | Description |
|---|---|---|
atrequired | string (date-time) | RFC 3339, from 1 minute ago to 366 days ahead |
reason | string |
DecisionRequest
| Field | Type | Description |
|---|---|---|
decisionrequired | "approve" | "deny" | |
scope | GrantScopeRequest | Required when approving; ignored when denying. |
DefaultPolicy
| Field | Type | Description |
|---|---|---|
rulesrequired | array of PolicyRule | |
updated_atrequired | string (date-time) | null | Null if never set. |
DefaultVersion
| Field | Type | Description |
|---|---|---|
default_versionrequired | string |
DesiredState
Desired state (changed through the API).
"running" | "suspended" | "stopped" | "destroyed"
DirectoryEntry
| Field | Type | Description |
|---|---|---|
namerequired | string | |
typerequired | "file" | "directory" | "symlink" | "other" | Symbolic links are not followed |
sizerequired | integer (int64) | |
modified_atrequired | string (date-time) | null | |
moderequired | string | Octal permission bits, for example |
DirectoryListing
| Field | Type | Description |
|---|---|---|
pathrequired | string | The path given in the request (unchanged) |
entriesrequired | array of DirectoryEntry | |
truncatedrequired | boolean | More than 10000 entries; the rest were cut off |
EgressAllow
| Field | Type | Description |
|---|---|---|
allowrequired | array of string |
Environment
| Field | Type | Description |
|---|---|---|
idrequired | string | |
end_user_idrequired | string | |
agent_versionrequired | string | null | |
templaterequired | string | null | The template version the environment runs ( |
resourcesrequired | Resources | Resource specification. |
desired_staterequired | DesiredState | Desired state (changed through the API). |
staterequired | EnvironmentState | Actual state (reported back by the host). |
idlerequired | IdleState | |
last_active_atrequired | string (date-time) | The most recent activity (the VM using CPU, a wake, keep-awake, a scheduled wakeup). Idle tiers are measured from this time. |
over_limitrequired | string | null | Which monthly limit was exceeded (a human-readable reason, for example |
created_atrequired | string (date-time) | |
updated_atrequired | string (date-time) |
EnvironmentConfig
Non-secret configuration for an environment. Inside the runtime unit, env is written to /run/temper/env, which the Agent service, exec and login shells load
(after the Agent package's own /opt/agent/env, so these values win); each file appears read-only at /run/temper/files/NAME.
Put secret values in secrets instead (PUT /v1/environments/{id}/secrets/{name}).
| Field | Type | Description |
|---|---|---|
env | ConfigEnv | Environment variables, at most 100 and 32 KiB in total. Names are letters, digits and |
files | ConfigFiles | Files by name, at most 20 and 256 KiB in total (decoded). Names are letters, digits, |
EnvironmentEgress
| Field | Type | Description |
|---|---|---|
allowrequired | array of string | |
inheritedrequired | boolean | true = the environment has no list of its own and uses the developer-level one. |
EnvironmentEvent
| Field | Type | Description |
|---|---|---|
idrequired | integer (int64) | Increasing cursor (for pagination); shared across all environments, so not contiguous |
kindrequired | string | Event kind, for example |
detailrequired | object | Event details; fields vary by kind. Actions registered by the Agent itself carry |
atrequired | string (date-time) |
EnvironmentEventList
| Field | Type | Description |
|---|---|---|
datarequired | array of EnvironmentEvent | |
nextrequired | integer (int64) | null | The |
EnvironmentList
| Field | Type | Description |
|---|---|---|
datarequired | array of Environment | |
nextrequired | string | null |
EnvironmentPolicy
| Field | Type | Description |
|---|---|---|
environment_idrequired | string | |
sourcerequired | "environment" | "developer" | "default" | Where the rules come from: the environment's own policy, the developer default, or the built-in behavior (empty |
rulesrequired | array of PolicyRule |
EnvironmentState
Actual state (reported back by the host).
"pending" | "running" | "suspended" | "stopped" | "destroyed" | "failed"
EnvironmentUsage
| Field | Type | Description |
|---|---|---|
active_hoursrequired | number | |
cpu_hoursrequired | number | |
memory_gib_hoursrequired | number | |
storage_gib_hoursrequired | number | |
egress_gibrequired | number | |
browser_hoursrequired | number | |
environment_idrequired | string | |
end_user_idrequired | string |
Error
| Field | Type | Description |
|---|---|---|
errorrequired | string | Machine-readable code:
|
messagerequired | string | |
environment_id | string | With |
ExecRequest
Provide exactly one of argv and command, and it must not be empty; strings must not contain NUL.
| Field | Type | Description |
|---|---|---|
argv | array of string | Executed as is, for example |
command | string | Run with |
env | map of string | Extra environment variables. Names consist of letters, digits and underscores and do not start with a digit; variables already set in agent.env or the Agent package's env cannot be overridden. |
cwd | string | Working directory (a path inside the runtime unit); defaults to the agent user's home directory. |
timeout_secs | integer | |
stdin | string | Standard input for the process (closed afterwards); if omitted, stdin is /dev/null. |
ExecResult
| Field | Type | Description |
|---|---|---|
exit_coderequired | integer | null | Exit code on normal exit; null if killed by a signal |
signalrequired | integer | null | The signal that killed the process (signal number) |
timed_outrequired | boolean | Killed for exceeding |
stdoutrequired | string | At most 1 MiB, decoded as UTF-8 |
stderrrequired | string | |
stdout_truncatedrequired | boolean | |
stderr_truncatedrequired | boolean | |
duration_msrequired | integer (int64) | Measured from when the control plane received the request (including waking and connecting) |
Grant
| Field | Type | Description |
|---|---|---|
idrequired | string | |
environment_idrequired | string | |
connectorrequired | string | |
categoryrequired | ActionCategory | Action category. |
scoperequired | "task" | "session" | "time_limited" | "permanent" | The scope the grant covers ("once" leaves no grant). |
scope_idrequired | string | null | The task / session id. |
untilrequired | string (date-time) | null | Expiry time for time_limited. |
approval_idrequired | string | null | |
created_atrequired | string (date-time) |
GrantList
| Field | Type | Description |
|---|---|---|
datarequired | array of Grant |
GrantScopeRequest
Grant scope. The task / session id must match the approval request's own task_id / session_id; until takes a future time in unix seconds
(it is called until here and time_limited in stored grants).
object | object | object | object | object
IdlePatch
IdleSecs
0 or 60–7776000.
integer
IdleSettingsInput
Idle thresholds (seconds); 0 = this tier is never applied automatically, otherwise 60–7776000 (90 days). Both thresholds count from the last activity: by default an environment is suspended after 6 hours idle and stopped after 7 days idle, so keep stop_after_secs larger than suspend_after_secs. With suspension turned off (0) the environment is never stopped either.
IdleState
| Field | Type | Description |
|---|---|---|
suspend_after_secsrequired | integer | |
stop_after_secsrequired | integer | |
keep_awake_untilrequired | string (date-time) | null | Until this time the environment will not be suspended by the idle tiers. |
KeepAwakeRequest
| Field | Type | Description |
|---|---|---|
secondsrequired | integer |
Me
Member
| Field | Type | Description |
|---|---|---|
idrequired | string | |
emailrequired | string | Lowercase. |
namerequired | string | null | |
rolerequired | MemberRole |
|
created_atrequired | string (date-time) |
MemberList
| Field | Type | Description |
|---|---|---|
datarequired | array of Member |
MemberRole
owner: manages members, API keys and the webhook, plus everything a member can do; member: day-to-day operations.
"owner" | "member"
OAuthClient
| Field | Type | Description |
|---|---|---|
providerrequired | OAuthProvider | |
client_idrequired | string | null | Registered by you; null if not registered. |
updated_atrequired | string (date-time) | null | |
platform_app_availablerequired | boolean | Whether the platform test app is configured (used when you have not registered your own app). |
redirect_urirequired | string |
OAuthClientList
| Field | Type | Description |
|---|---|---|
datarequired | array of OAuthClient |
OAuthClientRegistered
| Field | Type | Description |
|---|---|---|
providerrequired | OAuthProvider | |
client_idrequired | string | |
redirect_urirequired | string | The callback URL to register with the provider. |
OAuthProvider
"google" | "slack"
OutputChunk
| Field | Type | Description |
|---|---|---|
streamrequired | "stdout" | "stderr" | |
offsetrequired | integer (int64) | Offset of the first byte of this chunk |
datarequired | string | Decoded as UTF-8 (invalid bytes replaced with U+FFFD) |
Package
| Field | Type | Description |
|---|---|---|
versionrequired | string | |
sha256required | string | |
size_bytesrequired | integer (int64) | |
created_atrequired | string (date-time) |
PackageList
| Field | Type | Description |
|---|---|---|
datarequired | array of Package | |
default_versionrequired | string | null |
PolicyCheckRequest
| Field | Type | Description |
|---|---|---|
connectorrequired | string | A built-in connector ( |
categoryrequired | ActionCategory | Action category. |
task_id | string | Task-scoped grants apply only when this matches. |
session_id | string | Session-scoped grants apply only when this matches. |
PolicyCheckResult
| Field | Type | Description |
|---|---|---|
decisionrequired | "allow" | "ask" | "deny" | |
reasonrequired | "rule" | "grant" | "deny_rule" | "ask_rule" | "high_risk" | "no_rule" | "infrastructure_credential" |
|
max_scope | ScopeKind | Grant scope, from narrowest to widest: |
grant_id | string | |
matched_rulesrequired | array of integer | Indexes (from 0) of the rules in the effective policy that match this connector and category. |
sourcerequired | "environment" | "developer" | "default" | Where the effective rules come from. |
PolicyRule
A single rule. Omitting connector or category matches any value. When several rules match, deny > ask > allow.
When no rule matches, the built-in behavior applies: high-risk categories require approval (max_scope is permanent) and everything else is denied.
| Field | Type | Description |
|---|---|---|
connector | string | Connector (credential id), for example |
category | ActionCategory | Action category. |
effectrequired | "allow" | "deny" | "ask" | |
max_scope | ScopeKind | Only allowed on |
Process
| Field | Type | Description |
|---|---|---|
idrequired | string | |
argvrequired | array of string | The argv actually executed ( |
started_atrequired | integer (int64) | Start time (Unix seconds, not RFC 3339) |
runningrequired | boolean | |
exit | ProcessExit | Present only once the process has exited |
output_bytesrequired | integer (int64) | Total bytes output so far (stdout and stderr combined); continue reading from here next time |
output_startrequired | integer (int64) | Offset of the oldest byte still retained in the VM (anything earlier has been dropped) |
stdin_openrequired | boolean | stdin can still be written |
ProcessExit
| Field | Type | Description |
|---|---|---|
coderequired | integer | null | Exit code on normal exit; null if killed by a signal |
signal | integer | The signal that killed the process (signal number); the field is absent otherwise |
timed_outrequired | boolean |
ProcessList
| Field | Type | Description |
|---|---|---|
datarequired | array of Process |
ProcessOutput
| Field | Type | Description |
|---|---|---|
processrequired | Process | The process state when output reading began |
chunksrequired | array of OutputChunk | |
nextrequired | integer (int64) | The |
exitedrequired | boolean | The process was seen to exit during this read |
exitrequired | ProcessExit | null |
PutEgressRequest
| Field | Type | Description |
|---|---|---|
allowrequired | array of string | null | An exact domain or |
PutPolicyRequest
400 cases: allow for a high-risk category, max_scope on anything other than ask, more than 100 rules, or a connector that is empty or longer than 100 characters.
Unknown fields, or a wrong type or enum value, give 422 invalid_body.
| Field | Type | Description |
|---|---|---|
rulesrequired | array of PolicyRule |
PutSecretRequest
| Field | Type | Description |
|---|---|---|
valuerequired | string | The real value, at most 8192 bytes, with no newlines. Never returned by any endpoint afterwards. |
hostsrequired | array of string | The value is sent only to these exact domains (lowercase, without scheme, port or wildcards). |
paths | array of string | Allowlist of path prefixes (starting with |
header | string | The request header that receives the real value, default |
prefix | string | Header value = prefix + real value. Defaults to |
kind | SecretKind |
|
ReleaseBrowserLeaseRequest
| Field | Type | Description |
|---|---|---|
save | boolean | null | Whether a write lease saves the signed-in state; omitted or null means true. Only meaningful for write leases. |
Resources
Resource specification.
| Field | Type | Description |
|---|---|---|
cpusrequired | integer | |
memory_mibrequired | integer | Memory limit |
base_memory_mibrequired | integer | Base memory, no more than memory_mib |
disk_gibrequired | integer |
ResourcesInput
All optional; defaults are 2 vCPUs, a 4096 MiB memory limit, 1024 MiB base memory and a 10 GiB disk.
| Field | Type | Description |
|---|---|---|
cpus | integer | |
memory_mib | integer | |
base_memory_mib | integer | 256 to memory_mib |
disk_gib | integer |
Rollout
| Field | Type | Description |
|---|---|---|
idrequired | string | |
versionrequired | string | |
percentrequired | integer | |
batch_sizerequired | integer | |
max_failuresrequired | integer | |
staterequired | RolloutState | |
reasonrequired | string | null | Why it was rolled back (for an automatic rollback, the failed environments and errors; for a manual one, manual) |
created_atrequired | string (date-time) | |
updated_atrequired | string (date-time) | |
finished_atrequired | string (date-time) | null |
RolloutDetail
| Field | Type | Description |
|---|---|---|
idrequired | string | |
versionrequired | string | |
percentrequired | integer | |
batch_sizerequired | integer | |
max_failuresrequired | integer | |
staterequired | RolloutState | |
reasonrequired | string | null | Why it was rolled back (for an automatic rollback, the failed environments and errors; for a manual one, manual) |
created_atrequired | string (date-time) | |
updated_atrequired | string (date-time) | |
finished_atrequired | string (date-time) | null | |
environmentsrequired | array of RolloutMember |
RolloutList
| Field | Type | Description |
|---|---|---|
datarequired | array of Rollout |
RolloutMember
An environment whose version was changed by the rollout.
| Field | Type | Description |
|---|---|---|
environment_idrequired | string | |
from_versionrequired | string | null | The original version (restored on rollback) |
upgraded_atrequired | string (date-time) | |
deferredrequired | boolean | Not running when switched, so only the version was changed (effective at next start) without waiting for it to become healthy |
healthy_atrequired | string (date-time) | null | |
failed_atrequired | string (date-time) | null | Entered failed, or was not healthy within 10 minutes |
errorrequired | string | null | |
rolled_back_atrequired | string (date-time) | null |
RolloutState
"active" | "paused" | "completed" | "rolled_back"
Schedule
Either a recurring rule (cron + time zone) or a one-time rule (at); exactly one of the two.
| Field | Type | Description |
|---|---|---|
idrequired | string | |
sourcerequired | "agent" | "developer" | |
keyrequired | string | Name chosen by the registrant; the same key overwrites |
cronrequired | string | null | Standard 5 fields (minute hour day month weekday) |
tzrequired | string | null | IANA time zone; present together with cron |
atrequired | string (date-time) | null | |
next_atrequired | string (date-time) | null | Next occurrence (computed by the control plane) |
last_fired_atrequired | string (date-time) | null | |
created_atrequired | string (date-time) | |
updated_atrequired | string (date-time) |
ScheduleList
| Field | Type | Description |
|---|---|---|
datarequired | array of Schedule |
ScopeKind
Grant scope, from narrowest to widest: once < task < session < time_limited < permanent.
Note: in a decision request (DecisionRequest.scope.kind) the time-limited scope is written until; here (max_scope, and the scope of approvals and grants) it is called time_limited.
"once" | "task" | "session" | "time_limited" | "permanent"
Secret
A secret (without its value).
| Field | Type | Description |
|---|---|---|
namerequired | string | |
environment_idrequired | string | null | Set only for environment-level secrets; null for developer-level ones. |
hostsrequired | array of string | |
pathsrequired | array of string | |
headerrequired | string | |
prefixrequired | string | |
kindrequired | SecretKind |
|
created_atrequired | string (date-time) | |
updated_atrequired | string (date-time) | |
last_used_atrequired | string (date-time) | null | The last time the credential gateway substituted this value. |
SecretKind
standard: a key the Agent uses on the end user's behalf. Requests that use it go through the action policy as connector secret:NAME (GET/HEAD/OPTIONS count as read, other methods as write).
infrastructure: your own infrastructure credential, for example the token your Agent uses to connect back to your backend. It is still sent only to hosts and paths and every use is audited,
but requests that use it skip the action policy. A request that also carries a standard or built-in credential is judged by that credential.
"standard" | "infrastructure"
SecretList
| Field | Type | Description |
|---|---|---|
datarequired | array of Secret |
SetDefaultVersionRequest
| Field | Type | Description |
|---|---|---|
versionrequired | string |
SetLimitRequest
| Field | Type | Description |
|---|---|---|
environment_id | string | null | Omit for developer-level. |
metricrequired | UsageMetric |
|
monthly_limitrequired | number |
SetLimitResponse
| Field | Type | Description |
|---|---|---|
environment_idrequired | string | null | |
metricrequired | UsageMetric |
|
monthly_limitrequired | number |
SetOAuthClientRequest
| Field | Type | Description |
|---|---|---|
client_idrequired | string | |
client_secretrequired | string |
SetWebhookRequest
| Field | Type | Description |
|---|---|---|
urlrequired | string (uri) | |
rotate_secret | boolean |
SetWebhookResponse
| Field | Type | Description |
|---|---|---|
urlrequired | string | |
secretrequired | string | null | The new |
Signal
"TERM" | "KILL" | "INT" | "HUP"
SignalRequest
| Field | Type | Description |
|---|---|---|
signalrequired | Signal |
SpawnRequest
Same as ExecRequest; see each field for the differences.
| Field | Type | Description |
|---|---|---|
argv | array of string | |
command | string | |
env | map of string | |
cwd | string | |
timeout_secs | integer | Maximum run time, after which the process is killed; 0 = no limit |
stdin | boolean | You will write stdin later through attach; otherwise stdin is /dev/null |
StartRolloutRequest
| Field | Type | Description |
|---|---|---|
versionrequired | string | |
percentrequired | integer | |
batch_size | integer | Number of environments switched at the same time per batch |
max_failures | integer | Roll back automatically when failures exceed this number |
TakeoverRequestedEvent
| Field | Type | Description |
|---|---|---|
idrequired | string | |
typerequired | "browser.takeover_requested" | |
createdrequired | string (date-time) | |
environment_idrequired | string | |
datarequired | object |
Team
| Field | Type | Description |
|---|---|---|
idrequired | string | Developer id. |
namerequired | string | |
rolerequired | MemberRole |
|
TemplateCopy
Writes one file into the template.
| Field | Type | Description |
|---|---|---|
pathrequired | string | Absolute file path (no |
contentrequired | string | |
encoding | "utf8" | "base64" |
|
mode | string | null | Octal permissions, default |
TemplateList
| Field | Type | Description |
|---|---|---|
datarequired | array of object |
TemplateStart
The command environments with this template run when they have no Agent package: a string (run with /bin/sh -c) or an argv array, started in the last workdir.
With an Agent package, the package's /opt/agent/bin/start runs instead. Without either, the environment simply waits for exec.
string | array of string | null
TemplateState
building until the build finishes, then ready (environments can use it) or failed (see error and log).
"building" | "ready" | "failed"
TemplateStep
One build step, an object with exactly one key.
object | object | object | object
TemplateVersion
| Field | Type | Description |
|---|---|---|
namerequired | string | |
versionrequired | string | |
fromrequired | string | null | The base version ( |
staterequired | TemplateState |
|
errorrequired | string | null | Why the build failed. |
layer_countrequired | integer | Layers on top of the default runtime, including the base version's; 0 until the version is ready. |
startrequired | TemplateStart | The command environments with this template run when they have no Agent package: a string (run with |
logrequired | string | The last 64 KiB of the build log: each step's command and its output. |
created_atrequired | string (date-time) | |
finished_atrequired | string (date-time) | null |
TemplateVersionSummary
| Field | Type | Description |
|---|---|---|
versionrequired | string | |
staterequired | TemplateState |
|
fromrequired | string | null | |
created_atrequired | string (date-time) |
Usage
| Field | Type | Description |
|---|---|---|
fromrequired | string (date-time) | |
torequired | string (date-time) | |
totalrequired | UsageTotals | |
datarequired | array of EnvironmentUsage |
UsageLimit
| Field | Type | Description |
|---|---|---|
environment_idrequired | string | null | null means developer-level (the total across all environments). |
metricrequired | UsageMetric |
|
monthly_limitrequired | number | |
usedrequired | number | Used this month (UTC). |
updated_atrequired | string (date-time) |
UsageLimitList
| Field | Type | Description |
|---|---|---|
datarequired | array of UsageLimit |
UsageMetric
active_hours: hours the VM was running; cpu_hours: CPU time (hours); memory_gib_hours: VMM memory GiB × hours;
storage_gib_hours: actual data disk usage GiB × hours; egress_gib: egress traffic in GiB; browser_hours: browser lease hours.
"active_hours" | "cpu_hours" | "memory_gib_hours" | "storage_gib_hours" | "egress_gib" | "browser_hours"
UsageTotals
| Field | Type | Description |
|---|---|---|
active_hoursrequired | number | |
cpu_hoursrequired | number | |
memory_gib_hoursrequired | number | |
storage_gib_hoursrequired | number | |
egress_gibrequired | number | |
browser_hoursrequired | number |
Wakeup
| Field | Type | Description |
|---|---|---|
idrequired | string | |
atrequired | string (date-time) | |
reasonrequired | string | |
created_atrequired | string (date-time) |
WakeupList
| Field | Type | Description |
|---|---|---|
datarequired | array of Wakeup |
Webhook
| Field | Type | Description |
|---|---|---|
urlrequired | string | null | |
secret_rotated_atrequired | string (date-time) | null | |
previous_secret_expires_atrequired | string (date-time) | null | When the old secret expires after a rotation; null if there is no old secret still valid. |
WebhookEvent
| Field | Type | Description |
|---|---|---|
idrequired | string | |
typerequired | "environment.agent_schedule_set" | "environment.agent_schedule_deleted" | "environment.agent_keep_awake" | "environment.agent_keep_awake_released" | "environment.agent_request_rejected" | "environment.limit_exceeded" |
|
createdrequired | string (date-time) | |
environment_idrequired | string | |
datarequired | object | Event details; fields vary by event. Agent-related events carry |
WidenRolloutRequest
| Field | Type | Description |
|---|---|---|
percentrequired | integer | Not lower than the current percentage |
WriteFileResult
| Field | Type | Description |
|---|---|---|
pathrequired | string | The path given in the request (unchanged) |
sizerequired | integer (int64) | Number of bytes written |