API reference
Templates
Environment templates: system packages and tools layered on top of the platform's default runtime (Debian 13 with systemd), built from steps. The Agent package is the Agent itself; a template is the system around it. Each is versioned and upgraded on its own.
List templates and their versions
GET/v1/templates
Templates by name, each with its versions in creation order. Not paginated.
Responses
- 200Templates
TemplateList - 401Missing, invalid or revoked key
- 500Internal error (details are recorded only in server logs)
Get a template version
GET/v1/templates/{name}/versions/{version}
The build state, the reason a build failed, the number of layers and the tail of the build log.
Responses
- 200Template version
TemplateVersion - 401Missing, invalid or revoked key
- 404Does not exist, or does not belong to this developer (`no such resource`); for a nonexistent route `message` is `no such route`
- 500Internal error (details are recorded only in server logs)
Build a template version
POST/v1/templates/{name}/versions/{version}
Starts building a new, immutable version from steps and returns at once with state: building (202). Poll getTemplateVersion until the state is ready or failed.
The template is created with its first version. A version that already exists returns 409 version_exists, whatever the body; pick a new version instead.
The build runs in a temporary environment on top of from (another ready version of yours) or the platform's default runtime: each run step runs as root
inside the runtime with /bin/sh -c, and the files and packages it leaves behind become a layer. Egress during the build is limited to common package
registries (Debian, PyPI, npm, crates.io, GitHub releases) plus your developer-level allowlist. A step may run for up to 30 minutes and a whole build for up to an hour.
While it runs, the temporary environment appears in your environment list with end_user_id template-build:<name>:<version>; it is destroyed when the build ends.
A version with the same base, steps and start as one you already built reuses that build's layer instead of running the steps again.
Files written by copy steps are owned by root; add a run step with chown if the agent must write to them.
The build log records every command, so do not put secrets in steps.
from must be ready; a base that is still building or failed returns 409 template_not_ready, and one that does not exist returns 404.
The request body is limited to 8 MiB.
Request body application/json · CreateTemplateVersionRequest
| Field | Type | Description |
|---|---|---|
from | string | null | Base version as |
stepsrequired | array of TemplateStep | Build steps, run in order. All |
start | TemplateStart | The command environments with this template run when they have no Agent package: a string (run with |
Responses
- 202Build started
TemplateVersion - 400Invalid parameters: validation failed, the body is not valid JSON, or the query string could not be parsed (all returned in the same JSON shape).
- 401Missing, invalid or revoked key
- 404Does not exist, or does not belong to this developer (`no such resource`); for a nonexistent route `message` is `no such route`
- 409State conflict; `error` holds the specific code
- 413The request body exceeds the size limit (`payload_too_large`)
- 415Missing `Content-Type: application/json` (`unsupported_media_type`)
- 422The JSON does not match the schema: a missing field, a wrong type or enum value, or an unknown field (`invalid_body`)
- 500Internal error (details are recorded only in server logs)
Delete a template version
DELETE/v1/templates/{name}/versions/{version}
A version that is still building returns 409 template_building. A version used by an environment that has not been destroyed, or used as the base (from)
of another version, returns 409 template_in_use.
Responses
- 204Deleted
- 401Missing, invalid or revoked key
- 404Does not exist, or does not belong to this developer (`no such resource`); for a nonexistent route `message` is `no such route`
- 409State conflict; `error` holds the specific code
- 500Internal error (details are recorded only in server logs)