openapi: 3.1.0 info: title: Thyme Flow Management API version: 1.0.0 description: Workspace-scoped Flow management API. Reviewed against SDK 0.8.0 / CLI 0.10.0. Mutations require owner/admin membership as well as the stated scope. Deployment-specific profile, gas and runtime restrictions apply. servers: - url: '{baseUrl}' description: Set this to your deployment HTTP API base before making requests. The default is a placeholder. variables: baseUrl: default: https://api.example.com/http description: Full HTTP API base URL, including any deployment path prefix. Use development credentials only with the development API. security: - bearerAuth: [] tags: - name: Projects - name: Chains - name: Functions - name: Executables - name: Executions - name: Profiles - name: Secrets - name: Webhooks - name: Usage paths: /api/task/upload: post: tags: - Functions operationId: uploadFunctionRelease x-required-scope: functions:upload description: 'Upload the ZIP produced by the Thyme CLI. Metadata is JSON encoded in the data field. The checksum is SHA-256 of the complete ZIP, including permissions.json when present. Active name/tag/checksum matches return the existing release; this endpoint does not implement Idempotency-Key replay. Owner/admin membership and functions:upload are required. Required scope: `functions:upload`. Owner/admin membership is required.' requestBody: required: true content: multipart/form-data: schema: type: object required: - data - blob properties: data: type: string description: 'JSON-encoded metadata: workspaceId, projectId, taskName, checkSum (SHA-256), optional versionTag, optional schema (JSON string), optional definedCallbacks (string array). permissions.json must be inside the archive, not this metadata.' example: '{"workspaceId":"WORKSPACE_ID","projectId":"PROJECT_ID","taskName":"price-watcher","versionTag":"v1","checkSum":"SHA256_OF_ZIP"}' blob: type: string format: binary responses: '200': description: Created or existing immutable release. content: application/json: schema: type: object required: - taskId - versionTag - created properties: taskId: type: string versionTag: $ref: '#/components/schemas/VersionTag' created: type: boolean default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' summary: Upload function release /api/v1/chains: get: tags: - Chains operationId: listEnabledChains x-required-scope: chains:read parameters: - $ref: '#/components/parameters/WorkspaceId' responses: '200': $ref: '#/components/responses/DataArray' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' summary: List enabled chains description: 'Required scope: `chains:read`.' /api/v1/executables: get: tags: - Executables operationId: listExecutables x-required-scope: executables:read parameters: - $ref: '#/components/parameters/WorkspaceId' - $ref: '#/components/parameters/ProjectIdQuery' - $ref: '#/components/parameters/Limit' - $ref: '#/components/parameters/Cursor' responses: '200': $ref: '#/components/responses/Page' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' summary: List executables description: 'Required scope: `executables:read`.' post: tags: - Executables operationId: createExecutable x-required-scope: executables:write parameters: - $ref: '#/components/parameters/WorkspaceId' - $ref: '#/components/parameters/IdempotencyKey' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CreateExecutable' responses: '201': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' summary: Create executable description: 'Required scope: `executables:write`. Owner/admin membership is required.' /api/v1/executables/{executableId}: parameters: - $ref: '#/components/parameters/ExecutableId' - $ref: '#/components/parameters/WorkspaceId' get: tags: - Executables operationId: getExecutable x-required-scope: executables:read responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' summary: Get executable description: 'Required scope: `executables:read`.' delete: tags: - Executables operationId: deleteExecutable x-required-scope: executables:write parameters: - $ref: '#/components/parameters/IdempotencyKey' description: Delete a non-active executable (paused, provisioning, or error). Active executables must be paused first. Already-deleted executables are rejected. Requires executables:write and owner/admin membership. responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' summary: Delete executable /api/v1/executables/{executableId}/args: parameters: - $ref: '#/components/parameters/ExecutableId' - $ref: '#/components/parameters/WorkspaceId' patch: tags: - Executables summary: Update executable args operationId: updateExecutableArgs x-required-scope: executables:write description: 'Replace the JSON-encoded task args; function permission coverage is rechecked. Required scope: `executables:write`. Owner/admin membership is required.' parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' requestBody: required: true content: application/json: schema: type: object properties: args: &id001 type: string description: JSON-encoded task args. The API does not run all Console JSON/schema validation before storing this value. The task runtime validates args. /api/v1/executables/{executableId}/executions: parameters: - $ref: '#/components/parameters/ExecutableId' - $ref: '#/components/parameters/WorkspaceId' - $ref: '#/components/parameters/Limit' - $ref: '#/components/parameters/Cursor' get: tags: - Executions operationId: listExecutableExecutions x-required-scope: executions:read responses: '200': $ref: '#/components/responses/Page' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' summary: List executable executions description: 'Required scope: `executions:read`.' /api/v1/executables/{executableId}/function: parameters: - $ref: '#/components/parameters/ExecutableId' - $ref: '#/components/parameters/WorkspaceId' patch: tags: - Executables summary: Switch executable function operationId: switchExecutableFunction x-required-scope: executables:write description: 'The executable must be paused. Returns 202 while an atomic sandbox replacement is built. Poll pendingFunctionSwitch and lastFunctionSwitchError. Required scope: `executables:write`. Owner/admin membership is required.' parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '202': description: The executable must be paused. Returns 202 while an atomic sandbox replacement is built. Poll pendingFunctionSwitch and lastFunctionSwitchError. content: application/json: schema: $ref: '#/components/schemas/FunctionSwitchAccepted' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' requestBody: required: true content: application/json: schema: type: object properties: functionId: type: string args: *id001 required: - functionId /api/v1/executables/{executableId}/gas-mode: parameters: - $ref: '#/components/parameters/ExecutableId' - $ref: '#/components/parameters/WorkspaceId' patch: tags: - Executables summary: Update executable gas mode operationId: updateExecutableGasMode x-required-scope: executables:write description: 'Update gas configuration, subject to profile-specific restrictions. Required scope: `executables:write`. Owner/admin membership is required.' parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' requestBody: required: true content: application/json: schema: type: object properties: gasMode: &id003 type: string enum: - sponsored - self - self-funded description: Available modes depend on the profile kind. Roles profiles require sponsored mode. gasFallback: type: boolean sponsorshipProvider: &id002 type: string enum: - pimlico - alchemy description: Provider choice for eligible profiles. This field does not select managed Lift sponsorship. required: - gasMode /api/v1/executables/{executableId}/pause: parameters: - $ref: '#/components/parameters/ExecutableId' - $ref: '#/components/parameters/WorkspaceId' post: tags: - Executables summary: Pause executable operationId: pauseExecutable x-required-scope: executables:write description: 'Pause scheduling. Check any already-running execution separately. Required scope: `executables:write`. Owner/admin membership is required.' parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' /api/v1/executables/{executableId}/pinned: parameters: - $ref: '#/components/parameters/ExecutableId' - $ref: '#/components/parameters/WorkspaceId' patch: tags: - Executables summary: Set executable pinned operationId: setExecutablePinned x-required-scope: executables:write description: 'Set whether the executable is pinned in the Console. Required scope: `executables:write`. Owner/admin membership is required.' parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' requestBody: required: true content: application/json: schema: type: object properties: pinned: type: boolean required: - pinned /api/v1/executables/{executableId}/profile: parameters: - $ref: '#/components/parameters/ExecutableId' - $ref: '#/components/parameters/WorkspaceId' patch: tags: - Executables summary: Update executable profile operationId: updateExecutableProfile x-required-scope: executables:write description: 'Select a compatible active profile in this project; function permission coverage is rechecked. Required scope: `executables:write`. Owner/admin membership is required.' parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' requestBody: required: true content: application/json: schema: type: object properties: profileId: type: string required: - profileId /api/v1/executables/{executableId}/regenerate: parameters: - $ref: '#/components/parameters/ExecutableId' - $ref: '#/components/parameters/WorkspaceId' post: tags: - Executables summary: Regenerate executable operationId: regenerateExecutable x-required-scope: executables:write description: 'Request regeneration of the executable sandbox; resource state restrictions apply. Required scope: `executables:write`. Owner/admin membership is required.' parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' /api/v1/executables/{executableId}/reprovision: parameters: - $ref: '#/components/parameters/ExecutableId' - $ref: '#/components/parameters/WorkspaceId' post: tags: - Executables summary: Reprovision executable operationId: reprovisionExecutable x-required-scope: executables:write description: 'Request replacement of the executable sandbox through the provisioning lifecycle. Required scope: `executables:write`. Owner/admin membership is required.' parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' /api/v1/executables/{executableId}/resume: parameters: - $ref: '#/components/parameters/ExecutableId' - $ref: '#/components/parameters/WorkspaceId' post: tags: - Executables summary: Resume executable operationId: resumeExecutable x-required-scope: executables:write description: 'Resume a ready executable; profile readiness and function permission coverage are rechecked. Required scope: `executables:write`. Owner/admin membership is required.' parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' /api/v1/executables/{executableId}/run: parameters: - $ref: '#/components/parameters/ExecutableId' - $ref: '#/components/parameters/WorkspaceId' post: tags: - Executables summary: Run executable operationId: runExecutable x-required-scope: executables:run description: Queue a real execution. A successful request is not on-chain confirmation. Permission checks run asynchronously and can fail after this response. Requires executables:run and owner/admin membership. parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' /api/v1/executables/{executableId}/secrets: parameters: - $ref: '#/components/parameters/ExecutableId' - $ref: '#/components/parameters/WorkspaceId' patch: tags: - Executables summary: Update executable secrets operationId: updateExecutableSecrets x-required-scope: executables:write description: 'Replace all secret bindings. An empty array clears bindings; secret values are never returned. Required scope: `executables:write`. Owner/admin membership is required.' parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' requestBody: required: true content: application/json: schema: type: object properties: secretBindings: $ref: '#/components/schemas/SecretBindings' /api/v1/executables/{executableId}/simulate: parameters: - $ref: '#/components/parameters/ExecutableId' - $ref: '#/components/parameters/WorkspaceId' post: tags: - Executables summary: Simulate executable operationId: simulateExecutable x-required-scope: executables:run description: 'Queue a cloud dry run. This does not submit the resulting calls to the chain. Required scope: `executables:run`. Owner/admin membership is required.' parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' /api/v1/executables/{executableId}/sponsorship-provider: parameters: - $ref: '#/components/parameters/ExecutableId' - $ref: '#/components/parameters/WorkspaceId' patch: tags: - Executables summary: Update executable sponsorship provider operationId: updateExecutableSponsorshipProvider x-required-scope: executables:write description: 'Set the sponsorship provider for eligible profiles. Required scope: `executables:write`. Owner/admin membership is required.' parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' requestBody: required: true content: application/json: schema: type: object properties: sponsorshipProvider: *id002 required: - sponsorshipProvider /api/v1/executables/{executableId}/storage: parameters: - $ref: '#/components/parameters/ExecutableId' - $ref: '#/components/parameters/WorkspaceId' get: tags: - Executables operationId: getExecutableStorage description: 'Returns the complete JSON object when its serialized size is at most 16 MiB. Required scope: `storage:read`.' x-required-scope: storage:read responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' summary: Get executable storage patch: tags: - Executables operationId: replaceExecutableStorage description: 'Replaces the complete JSON object. The serialized value is limited to 16 MiB on this HTTP route. Required scope: `storage:write`. Owner/admin membership is required.' x-required-scope: storage:write parameters: - $ref: '#/components/parameters/IdempotencyKey' requestBody: required: true content: application/json: schema: type: object required: - expectedVersion - value properties: expectedVersion: type: integer minimum: 0 value: type: object additionalProperties: true responses: '200': description: The next storage version and whether the object changed. A no-op leaves the version unchanged. content: application/json: schema: type: object properties: data: type: object properties: version: type: integer changed: type: boolean required: - version - changed required: - data default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' summary: Replace executable storage /api/v1/executables/{executableId}/trigger: parameters: - $ref: '#/components/parameters/ExecutableId' - $ref: '#/components/parameters/WorkspaceId' patch: tags: - Executables summary: Update executable trigger operationId: updateExecutableTrigger x-required-scope: executables:write description: 'Replace the schedule. Cron and interval validation and workspace plan limits apply. Required scope: `executables:write`. Owner/admin membership is required.' parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' requestBody: required: true content: application/json: schema: type: object properties: trigger: $ref: '#/components/schemas/Trigger' required: - trigger /api/v1/executables/{executableId}/webhooks: parameters: - $ref: '#/components/parameters/ExecutableId' - $ref: '#/components/parameters/WorkspaceId' get: tags: - Webhooks operationId: listExecutableWebhooks x-required-scope: webhooks:read responses: '200': $ref: '#/components/responses/DataArray' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' summary: List executable webhooks description: 'Required scope: `webhooks:read`.' post: tags: - Webhooks operationId: createExecutableWebhook x-required-scope: webhooks:write parameters: - $ref: '#/components/parameters/IdempotencyKey' requestBody: required: true content: application/json: schema: type: object required: - name properties: name: type: string responses: '201': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' summary: Create executable webhook description: 'Required scope: `webhooks:write`. Owner/admin membership is required.' /api/v1/executions: get: tags: - Executions operationId: listProjectExecutions x-required-scope: executions:read parameters: - $ref: '#/components/parameters/WorkspaceId' - $ref: '#/components/parameters/ProjectIdQuery' - name: status in: query schema: type: string enum: - pending - running - simulating - submitted - confirmed - failed - skipped - $ref: '#/components/parameters/Limit' - $ref: '#/components/parameters/Cursor' responses: '200': $ref: '#/components/responses/Page' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' summary: List project executions description: 'Required scope: `executions:read`.' /api/v1/executions/{executionId}: parameters: - $ref: '#/components/parameters/ExecutionId' - $ref: '#/components/parameters/WorkspaceId' get: tags: - Executions operationId: getExecution x-required-scope: executions:read responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' summary: Get execution description: 'Required scope: `executions:read`.' /api/v1/executions/{executionId}/logs: parameters: - $ref: '#/components/parameters/ExecutionId' - $ref: '#/components/parameters/WorkspaceId' get: tags: - Executions operationId: getExecutionLogs x-required-scope: executions:read responses: '200': $ref: '#/components/responses/DataArray' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' summary: Get execution logs description: 'Required scope: `executions:read`.' /api/v1/functions: get: tags: - Functions operationId: listFunctionReleases x-required-scope: functions:read parameters: - $ref: '#/components/parameters/WorkspaceId' - $ref: '#/components/parameters/ProjectIdQuery' - name: name in: query schema: type: string description: Filter one function family and include version reservations. - $ref: '#/components/parameters/Limit' - $ref: '#/components/parameters/Cursor' responses: '200': $ref: '#/components/responses/Page' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' summary: List function releases description: 'Required scope: `functions:read`.' /api/v1/functions/{functionId}: parameters: - $ref: '#/components/parameters/FunctionId' - $ref: '#/components/parameters/WorkspaceId' get: tags: - Functions operationId: getFunctionRelease x-required-scope: functions:read responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' summary: Get function release description: 'Required scope: `functions:read`.' delete: tags: - Functions operationId: deleteFunctionRelease x-required-scope: functions:delete parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' summary: Delete function release description: 'Required scope: `functions:delete`. Owner/admin membership is required.' /api/v1/functions/{functionId}/copy: parameters: - $ref: '#/components/parameters/FunctionId' - $ref: '#/components/parameters/WorkspaceId' post: tags: - Functions operationId: copyFunctionRelease x-required-scope: functions:upload parameters: - $ref: '#/components/parameters/IdempotencyKey' requestBody: required: true content: application/json: schema: type: object required: - targetProjectId properties: targetProjectId: type: string name: type: string versionTag: $ref: '#/components/schemas/VersionTag' responses: '200': $ref: '#/components/responses/DataObject' '201': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' summary: Copy function release description: 'Required scope: `functions:upload`. Owner/admin membership is required.' /api/v1/functions/{functionId}/source: parameters: - $ref: '#/components/parameters/FunctionId' - $ref: '#/components/parameters/WorkspaceId' get: tags: - Functions operationId: getFunctionSource x-required-scope: functions:source responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' summary: Get function source description: 'Required scope: `functions:source`.' /api/v1/profiles: get: tags: - Profiles operationId: listProfiles x-required-scope: profiles:read parameters: - $ref: '#/components/parameters/WorkspaceId' - $ref: '#/components/parameters/ProjectIdQuery' - $ref: '#/components/parameters/Limit' - $ref: '#/components/parameters/Cursor' responses: '200': $ref: '#/components/responses/Page' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' summary: List profiles description: 'Required scope: `profiles:read`.' post: tags: - Profiles operationId: createProfile x-required-scope: profiles:write parameters: - $ref: '#/components/parameters/WorkspaceId' - $ref: '#/components/parameters/IdempotencyKey' requestBody: required: true content: application/json: schema: type: object required: - projectId - alias - chainId properties: projectId: type: string alias: type: string chainId: type: integer responses: '201': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' description: 'Creates a legacy EIP-7702 profile only where legacy creation is enabled. Safe and Roles profile onboarding requires owner wallet signatures in the Console. Required scope: profiles:write; owner/admin membership required.' summary: Create profile /api/v1/profiles/{profileId}: parameters: - $ref: '#/components/parameters/ProfileId' - $ref: '#/components/parameters/WorkspaceId' get: tags: - Profiles operationId: getProfile x-required-scope: profiles:read responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' summary: Get profile description: 'Required scope: `profiles:read`.' patch: tags: - Profiles operationId: renameProfile x-required-scope: profiles:write parameters: - $ref: '#/components/parameters/IdempotencyKey' requestBody: required: true content: application/json: schema: type: object required: - name properties: name: type: string responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' summary: Rename profile description: 'Required scope: `profiles:write`. Owner/admin membership is required.' /api/v1/profiles/{profileId}/archive: parameters: - $ref: '#/components/parameters/ProfileId' - $ref: '#/components/parameters/WorkspaceId' post: tags: - Profiles summary: Archive profile operationId: archiveProfile x-required-scope: profiles:write description: 'Archive a profile, subject to executable dependencies and profile state. Required scope: `profiles:write`. Owner/admin membership is required.' parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' /api/v1/profiles/{profileId}/retry: parameters: - $ref: '#/components/parameters/ProfileId' - $ref: '#/components/parameters/WorkspaceId' post: tags: - Profiles summary: Retry profile operationId: retryProfile x-required-scope: profiles:write description: Retry provisioning of a pending legacy profile. This route is not the Safe or Roles onboarding retry path. Requires profiles:write and owner/admin membership. parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' /api/v1/profiles/{profileId}/share: parameters: - $ref: '#/components/parameters/ProfileId' - $ref: '#/components/parameters/WorkspaceId' post: tags: - Profiles summary: Share profile operationId: shareProfile x-required-scope: profiles:write description: 'Share an active legacy profile with another project in the same workspace. Safe profiles cannot be shared. Required scope: `profiles:write`. Owner/admin membership is required.' parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '201': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' requestBody: required: true content: application/json: schema: type: object properties: targetProjectId: type: string alias: type: string required: - targetProjectId /api/v1/profiles/{profileId}/unarchive: parameters: - $ref: '#/components/parameters/ProfileId' - $ref: '#/components/parameters/WorkspaceId' post: tags: - Profiles summary: Unarchive profile operationId: unarchiveProfile x-required-scope: profiles:write description: 'Restore an archived profile where its kind and state permit it. Required scope: `profiles:write`. Owner/admin membership is required.' parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' /api/v1/projects: get: tags: - Projects operationId: listProjects x-required-scope: projects:read parameters: - $ref: '#/components/parameters/WorkspaceId' responses: '200': $ref: '#/components/responses/DataArray' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' summary: List projects description: 'Required scope: `projects:read`.' post: tags: - Projects operationId: createProject x-required-scope: projects:write parameters: - $ref: '#/components/parameters/WorkspaceId' - $ref: '#/components/parameters/IdempotencyKey' requestBody: required: true content: application/json: schema: type: object required: - name - slug properties: name: type: string slug: type: string description: type: string environment: type: string enum: - production - development responses: '201': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' summary: Create project description: 'Required scope: `projects:write`. Owner/admin membership is required.' /api/v1/projects/{projectId}: parameters: - $ref: '#/components/parameters/ProjectId' - $ref: '#/components/parameters/WorkspaceId' get: tags: - Projects operationId: getProject x-required-scope: projects:read responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' summary: Get project description: 'Required scope: `projects:read`.' patch: tags: - Projects operationId: updateProject x-required-scope: projects:write parameters: - $ref: '#/components/parameters/IdempotencyKey' requestBody: required: true content: application/json: schema: type: object properties: name: type: string description: type: string minProperties: 1 responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' summary: Update project description: 'Required scope: `projects:write`. Owner/admin membership is required.' /api/v1/secrets: get: tags: - Secrets operationId: listSecretMetadata x-required-scope: secrets:read parameters: - $ref: '#/components/parameters/WorkspaceId' - $ref: '#/components/parameters/ProjectIdQuery' responses: '200': $ref: '#/components/responses/DataArray' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' summary: List secret metadata description: 'Required scope: `secrets:read`.' post: tags: - Secrets operationId: createProjectSecret x-required-scope: secrets:write parameters: - $ref: '#/components/parameters/WorkspaceId' - $ref: '#/components/parameters/IdempotencyKey' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SecretWrite' responses: '201': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' summary: Create project secret description: 'Required scope: `secrets:write`. Owner/admin membership is required.' /api/v1/secrets/{secretId}: parameters: - $ref: '#/components/parameters/SecretId' - $ref: '#/components/parameters/WorkspaceId' patch: tags: - Secrets operationId: rotateProjectSecret x-required-scope: secrets:write parameters: - $ref: '#/components/parameters/IdempotencyKey' requestBody: required: true content: application/json: schema: type: object required: - value properties: value: type: string writeOnly: true responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' summary: Rotate project secret description: 'Required scope: `secrets:write`. Owner/admin membership is required.' delete: tags: - Secrets operationId: deleteProjectSecret x-required-scope: secrets:write parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' summary: Delete project secret description: 'Required scope: `secrets:write`. Owner/admin membership is required.' /api/v1/usage: get: tags: - Usage operationId: getCurrentFunctionsUsage x-required-scope: usage:read parameters: - $ref: '#/components/parameters/WorkspaceId' responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' summary: Get current functions usage description: 'Required scope: `usage:read`.' /api/v1/webhooks/{webhookId}: parameters: - $ref: '#/components/parameters/WebhookId' - $ref: '#/components/parameters/WorkspaceId' get: tags: - Webhooks operationId: getExecutableWebhook x-required-scope: webhooks:read responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' summary: Get executable webhook description: 'Required scope: `webhooks:read`.' patch: tags: - Webhooks operationId: renameExecutableWebhook x-required-scope: webhooks:write parameters: - $ref: '#/components/parameters/IdempotencyKey' requestBody: required: true content: application/json: schema: type: object required: - name properties: name: type: string responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' summary: Rename executable webhook description: 'Required scope: `webhooks:write`. Owner/admin membership is required.' delete: tags: - Webhooks operationId: revokeExecutableWebhook x-required-scope: webhooks:write parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' summary: Revoke executable webhook description: 'Required scope: `webhooks:write`. Owner/admin membership is required.' /api/v1/webhooks/{webhookId}/rotate: parameters: - $ref: '#/components/parameters/WebhookId' - $ref: '#/components/parameters/WorkspaceId' post: tags: - Webhooks operationId: rotateExecutableWebhook x-required-scope: webhooks:write parameters: - $ref: '#/components/parameters/IdempotencyKey' responses: '200': $ref: '#/components/responses/DataObject' default: $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '409': $ref: '#/components/responses/Error' summary: Rotate executable webhook description: 'Required scope: `webhooks:write`. Owner/admin membership is required.' components: securitySchemes: bearerAuth: type: http scheme: bearer parameters: WorkspaceId: name: X-Workspace-Id in: header required: false description: Required for an unbound key; a management credential is already workspace-bound. schema: type: string IdempotencyKey: name: Idempotency-Key in: header required: false description: 'Opaque 1–128 character key retained for 24 hours. Use a different key for every target resource and intended mutation: some fingerprints use the route template without the resource ID.' schema: type: string minLength: 1 maxLength: 128 Limit: name: limit in: query schema: type: integer minimum: 1 maximum: 200 default: 50 Cursor: name: cursor in: query schema: type: string ProjectId: name: projectId in: path required: true schema: type: string ProjectIdQuery: name: projectId in: query required: true schema: type: string FunctionId: name: functionId in: path required: true schema: type: string ExecutableId: name: executableId in: path required: true schema: type: string ExecutionId: name: executionId in: path required: true schema: type: string ProfileId: name: profileId in: path required: true schema: type: string SecretId: name: secretId in: path required: true schema: type: string WebhookId: name: webhookId in: path required: true schema: type: string responses: DataObject: description: Successful resource response. headers: X-Request-Id: schema: type: string Idempotency-Replayed: schema: type: string enum: - 'true' content: application/json: schema: type: object required: - data properties: data: {} DataArray: description: Successful collection response. headers: X-Request-Id: schema: type: string content: application/json: schema: type: object required: - data properties: data: type: array items: {} Page: description: Cursor-paginated collection. headers: X-Request-Id: schema: type: string content: application/json: schema: $ref: '#/components/schemas/Page' Error: description: Error response. headers: X-Request-Id: schema: type: string content: application/json: schema: $ref: '#/components/schemas/Error' schemas: Error: type: object required: - error - code properties: error: type: string code: type: string requestId: type: string retryAfterMs: type: integer reservedVersionTags: type: array items: type: string suggestedVersionTag: type: string message: type: string description: Additional diagnostic detail, when provided. status: type: string description: Permission-coverage verdict, when applicable. missing: type: array items: type: object additionalProperties: true reasons: type: array items: type: string Page: type: object required: - data - pagination properties: data: type: array items: {} pagination: type: object required: - cursor - isDone properties: cursor: type: string isDone: type: boolean versioning: type: object properties: functionName: type: string reservedVersionTags: type: array items: type: string suggestedVersionTag: type: string VersionTag: type: string minLength: 1 maxLength: 32 pattern: ^[a-z0-9][a-z0-9._-]{0,31}$ not: const: latest Trigger: oneOf: - type: object required: - type - cronspec properties: type: const: cron cronspec: type: string - type: object required: - type - intervalMs properties: type: const: interval intervalMs: type: integer minimum: 1 startAt: type: integer CreateExecutable: type: object required: - projectId - functionId - profileId - name - trigger properties: projectId: type: string functionId: type: string profileId: type: string name: type: string trigger: $ref: '#/components/schemas/Trigger' args: *id001 secretBindings: $ref: '#/components/schemas/SecretBindings' gasMode: *id003 gasFallback: type: boolean sponsorshipProvider: *id002 sandboxRuntime: type: string enum: - daytona - gvisor description: Where the task code runs. Defaults to daytona. gvisor is accepted only on deployments that have a gVisor sandbox runner configured. FunctionSwitchAccepted: type: object required: - success - requestId - state properties: success: const: true requestId: type: string state: const: rebuilding SecretWrite: type: object required: - projectId - key - value properties: projectId: type: string key: type: string value: type: string writeOnly: true SecretBindings: type: array items: type: object properties: secretId: type: string envKey: type: string description: Optional environment key override. required: - secretId