{"openapi":"3.1.0","info":{"title":"Mainbrella API","version":"1.0.0","description":"Account, billing, container, image build, and WebSocket API."},"servers":[{"url":"https://api.mainbrella.com"},{"url":"http://localhost:8787","description":"Local development"}],"tags":[{"name":"Operations"},{"name":"Authentication"},{"name":"API Keys"},{"name":"Subscriptions"},{"name":"Containers"},{"name":"Images"},{"name":"Internal"},{"name":"Admin"}],"components":{"securitySchemes":{"cookieAuth":{"type":"apiKey","in":"cookie","name":"mainbrella_session"},"sessionBearer":{"type":"http","scheme":"bearer","description":"Browser session value; container and image automation only."},"apiKeyBearer":{"type":"http","scheme":"bearer","description":"API key (mb_ prefix); container, image and SSH automation only. Create at mainbrella.com/api-keys/."},"nativeBearer":{"type":"http","scheme":"bearer","description":"Native app access token; native auth endpoints only."},"sshGateway":{"type":"http","scheme":"bearer","description":"Trusted SSH gateway secret."},"imageBuild":{"type":"http","scheme":"bearer","description":"Trusted image build service secret."},"stripeSignature":{"type":"apiKey","in":"header","name":"Stripe-Signature"},"monitoring":{"type":"http","scheme":"bearer","description":"Dedicated MONITORING_SECRET; operational observations and incidents only."}},"schemas":{"Capabilities":{"type":"object","properties":{"apiVersion":{"type":"string"},"authentication":{"type":"object","properties":{"apiKeys":{"type":"boolean"},"browserSessions":{"type":"boolean"},"browserTerminalCookieOnly":{"type":"boolean"}},"required":["apiKeys","browserSessions","browserTerminalCookieOnly"]},"containers":{"type":"object","properties":{"idempotentCreate":{"type":"boolean"},"creationRetentionMs":{"type":"integer","minimum":0},"generationRequired":{"type":"boolean"},"accountLimitsPath":{"type":"string"},"configurableDeadline":{"type":"boolean"}},"required":["idempotentCreate","creationRetentionMs","generationRequired","accountLimitsPath","configurableDeadline"]},"execution":{"type":"object","properties":{"foreground":{"type":"boolean"},"streaming":{"type":"boolean"},"background":{"type":"boolean"},"cancellation":{"type":"boolean"},"reconnect":{"type":"boolean"},"pty":{"type":"boolean"},"programmaticPty":{"type":"boolean"},"ptyResize":{"type":"boolean"},"stdin":{"type":"boolean"},"signals":{"type":"boolean"},"argv":{"type":"boolean"},"managedProcessListing":{"type":"boolean"},"processListing":{"type":"boolean"},"maxCommandBytes":{"type":"integer","minimum":0},"maxTimeoutMs":{"type":"integer","minimum":0},"maxOutputBytes":{"type":"integer","minimum":0},"maxConcurrentOperations":{"type":"integer","minimum":0},"maxManagedTimeoutMs":{"type":"integer","minimum":0},"retentionMs":{"type":"integer","minimum":0},"maxRetainedExecutions":{"type":"integer","minimum":0},"maxStdinChunkBytes":{"type":"integer","minimum":0},"maxStdinBytes":{"type":"integer","minimum":0},"maxPendingStdinBytes":{"type":"integer","minimum":0}},"required":["foreground","streaming","background","cancellation","reconnect","pty","programmaticPty","ptyResize","stdin","signals","argv","managedProcessListing","processListing","maxCommandBytes","maxTimeoutMs","maxOutputBytes","maxConcurrentOperations","maxManagedTimeoutMs","retentionMs","maxRetainedExecutions","maxStdinChunkBytes","maxStdinBytes","maxPendingStdinBytes"]},"files":{"type":"object","properties":{"read":{"type":"boolean"},"write":{"type":"boolean"},"binary":{"type":"boolean"},"atomicReplacement":{"type":"boolean"},"list":{"type":"boolean"},"stat":{"type":"boolean"},"mkdir":{"type":"boolean"},"delete":{"type":"boolean"},"move":{"type":"boolean"},"chmod":{"type":"boolean"},"watch":{"type":"boolean"},"sharedExecutionPool":{"type":"boolean"},"maxFileBytes":{"type":"integer","minimum":0},"maxPathBytes":{"type":"integer","minimum":0},"timeoutMs":{"type":"integer","minimum":0},"maxDirectoryEntries":{"type":"integer","minimum":0},"maxDirectoryOffset":{"type":"integer","minimum":0},"maxMetadataBytes":{"type":"integer","minimum":0}},"required":["read","write","binary","atomicReplacement","list","stat","mkdir","delete","move","chmod","watch","sharedExecutionPool","maxFileBytes","maxPathBytes","timeoutMs","maxDirectoryEntries","maxDirectoryOffset","maxMetadataBytes"]},"persistence":{"type":"object","properties":{"filesystemAfterStop":{"type":"boolean"},"snapshots":{"type":"boolean"},"workspaces":{"type":"boolean"},"exports":{"type":"boolean"},"memory":{"type":"boolean"},"volumes":{"type":"boolean"}},"required":["filesystemAfterStop","snapshots","workspaces","exports","memory","volumes"]},"observability":{"type":"object","properties":{"lifecycleEvents":{"type":"boolean"},"metrics":{"type":"boolean"},"webhooks":{"type":"boolean"},"otlp":{"type":"boolean"},"activityWebSocket":{"type":"boolean"},"eventRetentionMs":{"type":"integer","minimum":0},"maxLifecycleEvents":{"type":"integer","minimum":0},"maxMetricRangeMs":{"type":"integer","minimum":0},"metricBucketMs":{"type":"integer","minimum":0}},"required":["lifecycleEvents","metrics","webhooks","otlp","activityWebSocket","eventRetentionMs","maxLifecycleEvents","maxMetricRangeMs","metricBucketMs"]},"previews":{"type":"object","properties":{"supported":{"type":"boolean"},"signedUrls":{"type":"boolean"}},"required":["supported","signedUrls"]},"images":{"type":"object","properties":{"catalog":{"type":"boolean"},"availableCatalogPath":{"type":"string"},"customBuilds":{"type":"boolean"},"limits":{"type":"object","properties":{"maxBuildsPerMonth":{"type":"integer","minimum":0},"maxSavedImages":{"type":"integer","minimum":0},"maxContextBytes":{"type":"integer","minimum":0},"maxDockerfileBytes":{"type":"integer","minimum":0},"maxBuildSeconds":{"type":"integer","minimum":0}},"required":["maxBuildsPerMonth","maxSavedImages","maxContextBytes","maxDockerfileBytes","maxBuildSeconds"]}},"required":["catalog","availableCatalogPath","customBuilds","limits"]},"resources":{"type":"array","items":{"type":"object","properties":{"id":{"type":"string","enum":["lite","small","medium","large","xl"]},"name":{"type":"string"},"instance":{"type":"string"},"cpuVcpu":{"type":"number"},"memoryMiB":{"type":"number"},"diskGB":{"type":"number"},"computeUnits":{"type":"number"}},"required":["id","name","instance","cpuVcpu","memoryMiB","diskGB","computeUnits"]}},"networking":{"type":"object","properties":{"outboundInternet":{"type":"boolean"},"internetControl":{"type":"boolean"},"egressPolicies":{"type":"boolean"},"regionSelection":{"type":"boolean"}},"required":["outboundInternet","internetControl","egressPolicies","regionSelection"]},"access":{"type":"object","properties":{"maxTerminalConnections":{"type":"integer","minimum":0},"maxSSHAccessTokens":{"type":"integer","minimum":0},"sshTokenLifetimeMs":{"type":"integer","minimum":0}},"required":["maxTerminalConnections","maxSSHAccessTokens","sshTokenLifetimeMs"]}},"required":["apiVersion","authentication","containers","execution","files","persistence","observability","previews","images","resources","networking","access"]},"Execution":{"type":"object","properties":{"id":{"type":"string","format":"uuid"},"createdAt":{"type":"string","format":"date-time"},"startedAt":{"type":"string","format":"date-time"},"finishedAt":{"type":"string","format":"date-time"},"status":{"type":"string","enum":["starting","running","succeeded","failed","canceled","timed_out","output_limit","interrupted"]},"retainUntil":{"type":"integer"},"cursor":{"type":"integer","minimum":0},"outputBytes":{"type":"integer","minimum":0},"exitCode":{"type":["integer","null"]},"timedOut":{"type":"boolean"},"outputTruncated":{"type":"boolean"},"stdinEnabled":{"type":"boolean"},"stdinClosed":{"type":"boolean"},"stdinBytes":{"type":"integer","minimum":0},"pty":{"type":"object","properties":{"cols":{"type":"integer","minimum":1,"maximum":1000},"rows":{"type":"integer","minimum":1,"maximum":1000}},"required":["cols","rows"],"additionalProperties":false}},"required":["id","createdAt","startedAt","status","retainUntil","cursor","outputBytes","exitCode","timedOut","outputTruncated"]},"PreviewGrant":{"type":"object","properties":{"id":{"type":"string","pattern":"^[a-f0-9]{32}$"},"port":{"type":"integer","minimum":1024,"maximum":65535},"createdAt":{"type":"string","format":"date-time"},"expiresAt":{"type":"integer"}},"required":["id","port","createdAt","expiresAt"]},"Workspace":{"type":"object","properties":{"id":{"type":"string","format":"uuid"},"name":{"type":"string","minLength":1,"maxLength":80},"createdAt":{"type":"string","format":"date-time"},"expiresAt":{"type":"integer"},"source":{"type":"object","properties":{"id":{"type":"string"},"createdAt":{"type":"string","format":"date-time"}},"required":["id","createdAt"]},"size":{"type":"string","enum":["lite","small","medium","large","xl"]},"internet":{"type":"boolean"},"imageDigest":{"type":"string"},"imageId":{"type":"string"},"imageName":{"type":"string"},"catalogId":{"type":"string"},"bytes":{"type":["integer","null"],"minimum":0},"archived":{"type":"boolean"},"status":{"type":"string","enum":["saving","ready","failed","expired","deleted"]},"stopRequested":{"type":"boolean"},"stopCompleted":{"type":"boolean"}},"required":["id","name","createdAt","expiresAt","source","size","internet","imageDigest","bytes","archived","status","stopRequested","stopCompleted"]},"PublicUser":{"type":"object","properties":{"id":{"type":"string"},"email":{"type":["string","null"]},"name":{"type":"string"},"created_at":{"type":"string"},"dob":{"type":["string","null"]}},"required":["id","email","name","created_at","dob"]},"NativeTokens":{"type":"object","properties":{"access_token":{"type":"string"},"refresh_token":{"type":"string"},"token_type":{"type":"string","enum":["Bearer"]},"expires_in":{"type":"number"},"user":{"$ref":"#/components/schemas/PublicUser"}},"required":["access_token","refresh_token","token_type","expires_in","user"]},"SubscriptionState":{"type":"object","properties":{"subscription":{"type":["object","null"],"properties":{"id":{"type":"string"},"status":{"type":"string"},"cancel_at_period_end":{"type":"boolean"}},"required":["id","status","cancel_at_period_end"],"additionalProperties":{}},"trial":{"type":["object","null"],"properties":{"plan":{"type":"string","enum":["builder","pro","scale"]},"expires_at":{"type":"number","description":"Unix milliseconds; access ends automatically without charges."}},"required":["plan","expires_at"]},"plan":{"type":["string","null"],"enum":["builder","pro","scale",null]},"active":{"type":"boolean"},"valid_until":{"type":["number","null"],"description":"Unix milliseconds."},"pro":{"type":"boolean"},"configured":{"type":"boolean"},"scheduled_plan":{"type":["string","null"],"enum":["builder","pro","scale",null]},"scheduled_change_at":{"type":["number","null"],"description":"Unix seconds."}},"required":["subscription","trial","plan","active","valid_until","pro","configured","scheduled_plan","scheduled_change_at"]},"ContainerStatus":{"type":"object","properties":{"plan":{"type":["string","null"],"enum":["builder","pro","scale",null]},"active":{"type":"boolean"},"containers":{"type":"array","items":{"type":"object","properties":{"id":{"type":"string"},"name":{"type":"string"},"size":{"type":"string","enum":["lite","small","medium","large","xl"]},"computeUnits":{"type":"number"},"instance":{"type":"string","enum":["lite","standard-1","standard-2","standard-3","standard-4"]},"status":{"type":"string","enum":["starting","running"]},"internet":{"type":"boolean","description":"Immutable outbound internet selection; true for legacy generations."},"createdAt":{"type":"string"},"expiresAt":{"type":"string"},"imageId":{"type":"string"},"imageName":{"type":"string"},"catalogId":{"type":"string"},"workspaceId":{"type":"string","format":"uuid"},"imageDigest":{"type":"string","description":"Deployment-resolved immutable image reference for this generation; absent on older generations."}},"required":["id","name","size","computeUnits","instance","status","createdAt","expiresAt"]}},"limits":{"type":"object","properties":{"maxComputeUnitHours":{"type":"number"},"maxConcurrentComputeUnits":{"type":"number"},"maxContainers":{"type":"number"},"maxStartsPerMonth":{"type":"number"},"maxSessionMs":{"type":"number"},"idleTimeoutMs":{"type":"number"}},"required":["maxComputeUnitHours","maxConcurrentComputeUnits","maxContainers","maxStartsPerMonth","maxSessionMs","idleTimeoutMs"]},"usage":{"type":"object","properties":{"month":{"type":"string"},"starts":{"type":"number"},"computeUnitHours":{"type":"number"},"reservedComputeUnitHours":{"type":"number"},"availableComputeUnitHours":{"type":"number"},"concurrentComputeUnits":{"type":"number"}},"required":["month","starts","computeUnitHours","reservedComputeUnitHours","availableComputeUnitHours","concurrentComputeUnits"]},"sizes":{"type":"array","items":{"type":"object","properties":{"id":{"type":"string","enum":["lite","small","medium","large","xl"]},"name":{"type":"string"},"instance":{"type":"string"},"cpuVcpu":{"type":"number"},"memoryMiB":{"type":"number"},"diskGB":{"type":"number"},"computeUnits":{"type":"number"}},"required":["id","name","instance","cpuVcpu","memoryMiB","diskGB","computeUnits"]}},"imageCatalog":{"type":"array","items":{"type":"object","properties":{"id":{"type":"string"},"name":{"type":"string"}},"required":["id","name"]}}},"required":["plan","active","containers","limits","usage","sizes","imageCatalog"]},"FileEntry":{"type":"object","properties":{"name":{"type":"string"},"path":{"type":"string"},"type":{"type":"string","enum":["file","directory","symlink","fifo","socket","character","block","other"]},"size":{"type":"integer","minimum":0},"mode":{"type":"string"},"uid":{"type":"integer","minimum":0},"gid":{"type":"integer","minimum":0},"modifiedAt":{"type":"string","format":"date-time"},"linkTarget":{"type":"string"}},"required":["name","path","type","size","mode","uid","gid","modifiedAt"]},"Image":{"type":"object","properties":{"id":{"type":"string"},"name":{"type":"string"},"status":{"type":"string","enum":["queued","building","publishing","ready","failed"]},"createdAt":{"type":"string"},"updatedAt":{"type":"string"}},"required":["id","name","status","createdAt","updatedAt"]}},"parameters":{}},"paths":{"/health":{"get":{"operationId":"getHealth","tags":["Operations"],"summary":"Check API health","responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"ok":{"type":"boolean"}},"required":["ok"]}}}}}}},"/state":{"get":{"operationId":"getState","tags":["Operations"],"summary":"Increment and return the global durable visit counter","responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"visits":{"type":"number"}},"required":["visits"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/admin/tables":{"get":{"operationId":"listAdminTables","tags":["Admin"],"summary":"List tables available to the administrator","security":[{"cookieAuth":[]}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"tables":{"type":"array","items":{"type":"object","properties":{"id":{"type":"string"},"label":{"type":"string"},"group":{"type":"string"},"columns":{"type":"array","items":{"type":"string"}}},"required":["id","label","group","columns"]}}},"required":["tables"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/admin/tables/{table}":{"get":{"operationId":"getAdminTable","tags":["Admin"],"summary":"Search and page administrator table rows","security":[{"cookieAuth":[]}],"parameters":[{"schema":{"type":"string"},"required":true,"name":"table","in":"path"},{"schema":{"type":"integer","minimum":0,"maximum":1000000},"required":false,"name":"offset","in":"query"},{"schema":{"type":"string","maxLength":100},"required":false,"name":"q","in":"query"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"items":{"type":"array","items":{"type":"object","additionalProperties":{}}},"total":{"type":"number"},"offset":{"type":"number"},"limit":{"type":"number"}},"required":["items","total","offset","limit"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/capabilities":{"get":{"operationId":"getCapabilities","tags":["Operations"],"summary":"Discover API features and runtime limits","security":[],"description":"Public, read-only deployment contract. Requires no credentials, paid access, or provisioning. No query parameters. Does not establish live component health. Obtain account allowances and deployed image catalog through authenticated GET /containers. Unsupported features are explicit; customBuilds reflects build-service configuration. previews.supported requires explicit enablement, an isolated preview domain, routing database and runtime binding. Preview URLs use opaque bearer tokens rather than signatures, so signedUrls remains false.","responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Capabilities"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"405":{"description":"Method not allowed.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/activity":{"get":{"operationId":"connectAccountActivity","tags":["Containers"],"summary":"Subscribe to account activity over a read-only WebSocket","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Requires observability.activityWebSocket. API keys and session Bearer tokens authenticate in Authorization; browser cookies require an explicit trusted Origin. No query parameters or client-selected account IDs. The server sends {type:\"ready\"} on attachment: load an HTTP snapshot after this frame to repair missed changes. Future {type:\"changed\",id,resource,containerId,createdAt,executionId?} frames invalidate owned container lifecycle, managed execution status or preview metadata; resource is containers, executions or previews. Generations are exact ISO strings. No commands, output, credentials, preview URLs or activity history are sent. Events are best-effort hints, not a durable approval queue or replay journal. Disconnect/reconnect never executes work or renews a workspace lease. At most 8 sockets per account; connections close after 300 seconds to reauthenticate. Text ping receives pong automatically; other client messages close with 1008. Reconnect with backoff, wait for ready, then resync. Inspection requires no paid plan.","parameters":[{"schema":{"type":"string","enum":["websocket"]},"required":true,"name":"Upgrade","in":"header"},{"schema":{"type":"string","format":"uri"},"required":false,"name":"Origin","in":"header"}],"responses":{"101":{"description":"WebSocket upgraded. Ready and changed frames are JSON text."},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"405":{"description":"Method not allowed.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"426":{"description":"WebSocket upgrade required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/executions":{"get":{"operationId":"listContainerExecutions","tags":["Containers"],"summary":"List retained managed jobs for one generation","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Lists up to 32 retained records for the exact owned generation, including running/terminal state. Commands, argv, environment values and idempotency keys are excluded. This is managed-job listing, not a guest-wide OS process table. Available after stop and during billing outages; never starts a machine or renews activity.","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"executions":{"type":"array","items":{"$ref":"#/components/schemas/Execution"}}},"required":["executions"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}},"post":{"operationId":"startContainerExecution","tags":["Containers"],"summary":"Start an idempotent managed shell command","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Requires owned running generation and paid access. Supply exactly one of command (shell) or argv (direct executable/arguments, no shell expansion). Optional cwd/env, stdin=true and pty={cols,rows}. PTY requires stdin=true and combines stdout/stderr on stdout; terminal line endings and input behavior apply. Closing input may hang up the PTY. Dimensions cap at 1000. Resize with the managed job endpoint. stdin defaults to closed/EOF. Idempotency-Key is required and scoped to that generation. Changed command/argv, timeout, input mode, cwd, env or initial terminal dimensions conflicts. Matching retries return retained execution. Command, argv and env values are not retained. Disconnect does not cancel. Timeout defaults to 30000 ms, caps at 900000 ms and the hard deadline. Active work renews idle activity. Shares the four-operation pool with foreground commands/files. Combined output caps at 1 MiB and 512 chunks. Up to 32 records are retained for 3600000 ms from admission; admission rejects when full. Cancellation targets the operation process group; deliberately detached processes remain bounded by the machine lease. A runtime restart interrupts unfinished work and stops its generation. No command is replayed. Requires GNU timeout in the image. Cookie mutations require trusted Origin.","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"},{"schema":{"type":"string","pattern":"^[A-Za-z0-9_-]{1,128}$"},"required":true,"name":"Idempotency-Key","in":"header"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"anyOf":[{"type":"object","properties":{"command":{"type":"string","minLength":1,"maxLength":16384},"pty":{"type":"object","properties":{"cols":{"type":"integer","minimum":1,"maximum":1000},"rows":{"type":"integer","minimum":1,"maximum":1000}},"required":["cols","rows"],"additionalProperties":false,"description":"Requires stdin=true; combined output on stdout with terminal line discipline."},"timeoutMs":{"type":"integer","minimum":1,"maximum":900000},"stdin":{"type":"boolean"},"cwd":{"type":"string","minLength":1,"maxLength":4096,"description":"Absolute UTF-8 working directory; no dot or parent segments."},"env":{"type":"object","additionalProperties":{"type":"string","maxLength":4096},"description":"At most 64 names and 16 KiB of encoded JSON. Variables other than PATH are not inherited by the provider exec API."}},"required":["command"],"additionalProperties":false},{"type":"object","properties":{"argv":{"type":"array","items":{"type":"string","maxLength":16384},"minItems":1,"maxItems":64,"description":"Total argv bytes at most the shared command limit."},"pty":{"type":"object","properties":{"cols":{"type":"integer","minimum":1,"maximum":1000},"rows":{"type":"integer","minimum":1,"maximum":1000}},"required":["cols","rows"],"additionalProperties":false,"description":"Requires stdin=true; combined output on stdout with terminal line discipline."},"timeoutMs":{"type":"integer","minimum":1,"maximum":900000},"stdin":{"type":"boolean"},"cwd":{"type":"string","minLength":1,"maxLength":4096,"description":"Absolute UTF-8 working directory; no dot or parent segments."},"env":{"type":"object","additionalProperties":{"type":"string","maxLength":4096},"description":"At most 64 names and 16 KiB of encoded JSON. Variables other than PATH are not inherited by the provider exec API."}},"required":["argv"],"additionalProperties":false}]}}}},"responses":{"202":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Execution"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"413":{"description":"Request too large.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/executions/{executionId}/stdin":{"post":{"operationId":"writeContainerExecutionInput","tags":["Containers"],"summary":"Send raw bytes to an owned managed job","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Requires a running job created with stdin=true and a running paid generation. Writes are ordered and backpressure-aware. At most 65536 bytes per request, 1048576 accepted bytes per job and 262144 pending bytes. Accepted bytes remain counted after ambiguous writes. Input is not retained, replayed or retried. A 30-second response bound does not undo an accepted write; reconcile application state before sending again. Cookie mutations require trusted Origin.","parameters":[{"schema":{"type":"string","format":"uuid"},"required":true,"name":"executionId","in":"path"},{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"}],"requestBody":{"required":false,"content":{"application/octet-stream":{"schema":{"type":"string","format":"binary"}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"bytes":{"type":"integer","minimum":0},"stdinClosed":{"type":"boolean"}},"required":["bytes","stdinClosed"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"413":{"description":"Request too large.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}},"delete":{"operationId":"closeContainerExecutionInput","tags":["Containers"],"summary":"Send EOF to an owned managed job","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Closes input after previously accepted writes. Does not cancel the job. Available as an owned cleanup operation during billing outages. A stopped/closed input returns a conflict. Cookie mutations require trusted Origin.","parameters":[{"schema":{"type":"string","format":"uuid"},"required":true,"name":"executionId","in":"path"},{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"bytes":{"type":"number","enum":[0]},"stdinClosed":{"type":"boolean"}},"required":["bytes","stdinClosed"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/executions/{executionId}/signal":{"post":{"operationId":"signalContainerExecution","tags":["Containers"],"summary":"Signal the process group of an owned managed job","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Accepts SIGINT, SIGTERM or SIGKILL. Signal delivery is a request, not proof of exit; inspect retained state/output. SIGKILL requests cancellation. Other signals may be handled or ignored. No arbitrary PID input. Cleanup checks the current generation again before signaling and remains available during billing outages. Cookie mutations require trusted Origin.","parameters":[{"schema":{"type":"string","format":"uuid"},"required":true,"name":"executionId","in":"path"},{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"signal":{"type":"string","enum":["SIGINT","SIGTERM","SIGKILL"]}},"required":["signal"],"additionalProperties":false}}}},"responses":{"202":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Execution"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/executions/{executionId}/resize":{"post":{"operationId":"resizeContainerExecutionTerminal","tags":["Containers"],"summary":"Resize an owned managed pseudo-terminal","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Requires the exact running paid generation and a live job started with pty. Each dimension is 1–1000. Does not create, attach to arbitrary guest processes or change the original idempotency fingerprint. Disconnecting the output stream only detaches. Cookie mutations require trusted Origin.","parameters":[{"schema":{"type":"string","format":"uuid"},"required":true,"name":"executionId","in":"path"},{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"cols":{"type":"integer","minimum":1,"maximum":1000},"rows":{"type":"integer","minimum":1,"maximum":1000}},"required":["cols","rows"],"additionalProperties":false}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Execution"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/executions/{executionId}":{"get":{"operationId":"getContainerExecution","tags":["Containers"],"summary":"Read retained execution state and output","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Owned generation only. Available after stop and during billing outages; never starts a machine or renews idle time. Expired/mismatched records return 404. Does not reveal the command or idempotency key.","parameters":[{"schema":{"type":"string","format":"uuid"},"required":true,"name":"executionId","in":"path"},{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"allOf":[{"$ref":"#/components/schemas/Execution"},{"type":"object","properties":{"stdout":{"type":"string"},"stderr":{"type":"string"}},"required":["stdout","stderr"]}]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}},"delete":{"operationId":"cancelContainerExecution","tags":["Containers"],"summary":"Request cancellation of an owned execution","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Idempotent cancellation request. 202 returns the observed record; poll until terminal. Available during billing outages and after stop. Cannot affect another generation. Cookie mutations require trusted Origin.","parameters":[{"schema":{"type":"string","format":"uuid"},"required":true,"name":"executionId","in":"path"},{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"}],"responses":{"202":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Execution"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/executions/{executionId}/events":{"get":{"operationId":"streamContainerExecution","tags":["Containers"],"summary":"Stream and replay execution output with a cursor","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"SSE stdout/stderr events contain sequence, type and data; id is the sequence. Resume with cursor equal to the last received id. Cursor must not exceed retained output. status event contains execution metadata; terminal status ends the stream. Streams rotate after 30000 ms and emit heartbeat comments. Disconnect only detaches. Maximum eight streams per container. Available for retained owned generations during billing outages.","parameters":[{"schema":{"type":"string","format":"uuid"},"required":true,"name":"executionId","in":"path"},{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"integer","minimum":0},"required":false,"name":"cursor","in":"query"},{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"}],"responses":{"200":{"description":"Server-sent execution output events.","content":{"text/event-stream":{"schema":{"type":"string"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/previews":{"post":{"operationId":"createContainerPreview","tags":["Containers"],"summary":"Issue a protected application preview URL","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Available only on an explicitly configured isolated preview deployment. Requires owned running generation and paid access. Links are bearer capabilities: anyone with the URL may access that port until expiry or revocation. URL returned once; stored routing data contains only the token hash. Ports 1024–65535; SSH and privileged ports excluded. Up to 8 active grants per generation. TTL defaults to 900 seconds and is clipped to the hard deadline; issuance does not extend the lease. HTTP and WebSockets use the same origin. Cookies are stripped. The app must already be listening. Cookie mutations require trusted Origin. Requests cap at 1024 bytes. Index-write failure triggers grant revocation; partial cleanup returns 503 with previewId for retry. Lost responses: list and revoke, then issue a new URL.","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"port":{"type":"integer","minimum":1024,"maximum":65535},"ttlSeconds":{"type":"integer","minimum":60,"maximum":3600}},"required":["port"],"additionalProperties":false}}}},"responses":{"201":{"description":"Successful response.","content":{"application/json":{"schema":{"allOf":[{"$ref":"#/components/schemas/PreviewGrant"},{"type":"object","properties":{"url":{"type":"string","format":"uri"}},"required":["url"]}]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"413":{"description":"Request too large.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Unavailable or partial failure; retry revocation with previewId when supplied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"previewId":{"type":"string","pattern":"^[a-f0-9]{32}$"}},"required":["error"]}}}}}},"get":{"operationId":"listContainerPreviews","tags":["Containers"],"summary":"List active grants for an owned running generation","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Requires paid access and exact running generation. Remains available when issuance is disabled. Returns grant metadata only, including grants left by lost issuance responses; no URLs, raw tokens or hashes. Does not create or restart a machine.","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"previews":{"type":"array","items":{"$ref":"#/components/schemas/PreviewGrant"},"maxItems":8}},"required":["previews"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}},"delete":{"operationId":"revokeContainerPreview","tags":["Containers"],"summary":"Revoke a preview and close its active transports","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Owner only; requires paid access and exact running generation. Remains available when issuance is disabled. Idempotent within that generation. Removes the owner-scoped route before closing runtime HTTP/WebSocket transports. Both operations are attempted even when one fails. Partial failures return 503 with previewId; retry the same request. Cookie mutations require trusted Origin.","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string","pattern":"^[a-f0-9]{32}$"},"required":true,"name":"previewId","in":"query"},{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"revoked":{"type":"boolean","enum":[true]}},"required":["revoked"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Unavailable or partial failure; retry revocation with previewId when supplied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"previewId":{"type":"string","pattern":"^[a-f0-9]{32}$"}},"required":["error"]}}}}}}},"/status":{"get":{"operationId":"getOperationalStatus","tags":["Operations"],"summary":"Read component observations and incidents","security":[],"description":"Public status with evidence scope. Missing observations or observations older than 15 minutes are unknown. Reachability and control-plane checks do not establish full workflow health. Up to 50 incidents are returned with active incidents first; active incidents prevent an overall operational state. No provisioning occurs.","responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"state":{"type":"string","enum":["operational","degraded","outage","unknown"]},"generatedAt":{"type":"string","format":"date-time"},"staleAfterMs":{"type":"integer"},"components":{"type":"array","items":{"type":"object","properties":{"component":{"type":"string","enum":["website","api","auth","provisioning","ssh","images","billing"]},"state":{"type":"string","enum":["operational","degraded","outage","unknown"]},"stale":{"type":"boolean"},"scope":{"type":["string","null"],"enum":["reachability","control_plane","synthetic",null]},"latencyMs":{"type":["integer","null"]},"checkedAt":{"type":["string","null"],"format":"date-time"}},"required":["component","state","stale","scope","latencyMs","checkedAt"]}},"incidents":{"type":"array","items":{"type":"object","properties":{"id":{"type":"string","format":"uuid"},"component":{"type":"string","enum":["website","api","auth","provisioning","ssh","images","billing"]},"title":{"type":"string"},"state":{"type":"string","enum":["investigating","identified","monitoring","resolved"]},"message":{"type":"string"},"started_at":{"type":"string","format":"date-time"},"updated_at":{"type":"string","format":"date-time"},"resolved_at":{"type":["string","null"],"format":"date-time"}},"required":["id","component","title","state","message","started_at","updated_at","resolved_at"]}}},"required":["state","generatedAt","staleAfterMs","components","incidents"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/status/history":{"get":{"operationId":"getStatusHistory","tags":["Operations"],"summary":"Read recent component observations","security":[],"description":"Returns up to 100 observations from the past 31 days, optionally for one component. Follow next.before and next.beforeId together to paginate without skipping samples with equal timestamps; beforeId requires before. Expired observations are excluded even before storage maintenance; incidents are retained separately. Does not estimate availability from missing samples.","parameters":[{"schema":{"type":"string","format":"date-time"},"required":false,"name":"before","in":"query"},{"schema":{"type":"integer","exclusiveMinimum":0},"required":false,"name":"beforeId","in":"query"},{"schema":{"type":"string","enum":["website","api","auth","provisioning","ssh","images","billing"]},"required":false,"name":"component","in":"query"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"observations":{"type":"array","items":{"type":"object","properties":{"id":{"type":"integer"},"component":{"type":"string","enum":["website","api","auth","provisioning","ssh","images","billing"]},"state":{"type":"string","enum":["operational","degraded","outage","unknown"]},"scope":{"type":"string","enum":["reachability","control_plane","synthetic"]},"latencyMs":{"type":["integer","null"]},"checkedAt":{"type":"string","format":"date-time"}},"required":["id","component","state","scope","latencyMs","checkedAt"]}},"retentionDays":{"type":"integer"},"next":{"type":["object","null"],"properties":{"before":{"type":"string","format":"date-time"},"beforeId":{"type":"integer"}},"required":["before","beforeId"]}},"required":["observations","retentionDays","next"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/internal/status/observations":{"post":{"operationId":"recordStatusObservations","tags":["Internal"],"summary":"Record bounded operational observations","security":[{"monitoring":[]}],"description":"Requires configured MONITORING_SECRET Bearer credential. At most seven distinct components per request. Timestamp is assigned by the server. No user/API key authentication.","requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"observations":{"type":"array","items":{"type":"object","properties":{"component":{"type":"string","enum":["website","api","auth","provisioning","ssh","images","billing"]},"state":{"type":"string","enum":["operational","degraded","outage","unknown"]},"scope":{"type":"string","enum":["reachability","control_plane","synthetic"]},"latencyMs":{"type":"integer","minimum":0,"maximum":300000}},"required":["component","state","scope"],"additionalProperties":false},"minItems":1,"maxItems":7}},"required":["observations"],"additionalProperties":false}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"ok":{"type":"boolean"},"checkedAt":{"type":"string","format":"date-time"}},"required":["ok","checkedAt"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/internal/status/incidents":{"post":{"operationId":"recordStatusIncident","tags":["Internal"],"summary":"Create or update a public incident","security":[{"monitoring":[]}],"description":"Requires configured MONITORING_SECRET. Upserts by UUID and preserves initial timestamp. Component cannot change; resolved incidents cannot reopen. Title/message are public operator-authored text.","requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"id":{"type":"string","format":"uuid"},"component":{"type":"string","enum":["website","api","auth","provisioning","ssh","images","billing"]},"title":{"type":"string","minLength":1,"maxLength":160},"state":{"type":"string","enum":["investigating","identified","monitoring","resolved"]},"message":{"type":"string","minLength":1,"maxLength":2000}},"required":["id","component","title","state","message"],"additionalProperties":false}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"ok":{"type":"boolean"},"id":{"type":"string","format":"uuid"}},"required":["ok","id"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/events":{"get":{"operationId":"listContainerLifecycleEvents","tags":["Containers"],"summary":"Read lifecycle history for an owned generation","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Read-only, available during billing outages and after stop. Does not provision, renew activity or contact the guest. Events have stable IDs and increasing slot-wide sequence numbers; filter by exact generation. Retention 604800000 ms, bounded to 256 events per machine slot across generations. Deduplicate by id, order by sequence and use nextCursor for pagination. historyTruncated reports when the starting event has been pruned. A started event establishes readiness; starting alone does not. Failed/stopped observations use bounded reason codes, never provider exception text. Natural-stop timestamps record when the control plane observed stop, not an exact guest timestamp. Legacy/expired generations without observations return 404. Customer webhooks are not yet available.","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"integer","minimum":0},"required":false,"name":"cursor","in":"query"},{"schema":{"type":"integer","minimum":1,"maximum":100},"required":false,"name":"limit","in":"query"},{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"events":{"type":"array","items":{"type":"object","properties":{"id":{"type":"string","format":"uuid"},"sequence":{"type":"integer","exclusiveMinimum":0},"createdAt":{"type":"string","format":"date-time"},"occurredAt":{"type":"string","format":"date-time"},"type":{"type":"string","enum":["starting","started","failed","stopped"]},"reason":{"type":"string"},"size":{"type":"string"},"retainUntil":{"type":"integer"}},"required":["id","sequence","createdAt","occurredAt","type","size","retainUntil"]}},"nextCursor":{"type":"integer","minimum":0},"hasMore":{"type":"boolean"},"historyTruncated":{"type":"boolean"},"retainForMs":{"type":"integer"}},"required":["events","nextCursor","hasMore","historyTruncated","retainForMs"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/metrics":{"get":{"operationId":"getContainerWorkloadMetrics","tags":["Containers"],"summary":"Read provider workload metric history for an owned generation","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Disabled until explicit operator configuration/qualification. Requires observability.metrics capability. Reads provider analytics using an opaque generation label; no guest exec or lease renewal. Requested range stays within that generation, the last seven days and 86400000 ms. Default last hour, 60000 ms buckets, bounded 1441 rows. Half-open [from,to); first bucket can begin before an unaligned from. Samples can be delayed/adaptively sampled; empty/legacy data is unobserved, never zero or healthy. CPU seconds and memory peak bytes come from workload metrics; diskUsagePeak preserves the provider value pending unit qualification. This is neither billing resource allocation nor public service health. Credentials and provider identity labels stay in the control plane.","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":false,"name":"from","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":false,"name":"to","in":"query"},{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"id":{"type":"string"},"createdAt":{"type":"string","format":"date-time"},"from":{"type":"string","format":"date-time"},"to":{"type":"string","format":"date-time"},"bucketMs":{"type":"integer"},"source":{"type":"string","enum":["cloudflare-workload-analytics"]},"state":{"type":"string","enum":["observed","unobserved"]},"buckets":{"type":"array","items":{"type":"object","properties":{"at":{"type":"string","format":"date-time"},"samples":{"type":"integer","exclusiveMinimum":0},"cpuSeconds":{"type":["number","null"],"minimum":0},"memoryPeakBytes":{"type":["number","null"],"minimum":0},"diskUsagePeak":{"type":["number","null"],"minimum":0,"description":"Provider diskUsage maximum. Unit qualification remains an operator rollout gate; do not label it as bytes or billing usage."}},"required":["at","samples","cpuSeconds","memoryPeakBytes","diskUsagePeak"]}}},"required":["id","createdAt","from","to","bucketMs","source","state","buckets"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/webhook":{"get":{"operationId":"getContainerWebhook","tags":["Containers"],"summary":"Read an owned generation webhook","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Available after stop and during billing outages. One configured destination per exact generation, up to 32 retained configurations per slot. Signing secrets are never returned by reads. No guest request or lease renewal.","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"webhook":{"type":["object","null"],"properties":{"id":{"type":"string","format":"uuid"},"url":{"type":"string","maxLength":2048,"format":"uri"},"createdAt":{"type":"string","format":"date-time"},"configuredAt":{"type":"string","format":"date-time"},"retainUntil":{"type":"integer"}},"required":["id","url","createdAt","configuredAt","retainUntil"]}},"required":["webhook"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}},"put":{"operationId":"configureContainerWebhook","tags":["Containers"],"summary":"Configure and rotate an owned generation webhook","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Disabled until API/runtime operator configuration. Requires an exact live paid generation. HTTPS targets must match an operator-controlled relay allowlist; arbitrary customer domains, IPs, credentials, custom ports and redirects are unsupported. Body caps at 4096 bytes. Returns a new signingSecret once; encrypted in runtime storage and never sent to the guest. Every PUT rotates the configuration/secret and clears old delivery attempts; no automatic retries. If a response is lost, reconcile with GET and explicitly rotate again if needed. Optional replayFromCursor queues retained generation events after that cursor; otherwise only future events. Configuration expires seven days after setup; deliveries expire with configuration or event retention, whichever is earlier. Cookie mutations require trusted Origin.","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"url":{"type":"string","maxLength":2048,"format":"uri"},"replayFromCursor":{"type":"integer","minimum":0}},"required":["url"],"additionalProperties":false}}}},"responses":{"201":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"webhook":{"type":"object","properties":{"id":{"type":"string","format":"uuid"},"url":{"type":"string","maxLength":2048,"format":"uri"},"createdAt":{"type":"string","format":"date-time"},"configuredAt":{"type":"string","format":"date-time"},"retainUntil":{"type":"integer"}},"required":["id","url","createdAt","configuredAt","retainUntil"]},"signingSecret":{"type":"string"}},"required":["webhook","signingSecret"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}},"delete":{"operationId":"removeContainerWebhook","tags":["Containers"],"summary":"Remove an owned webhook and future deliveries","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Owned cleanup remains available during billing outages and after stop. Cancels in-flight requests and removes queued attempts. A receiver may already have accepted an in-flight request; removal cannot undo delivery. Does not affect replacement generations. Cookie mutations require trusted Origin.","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"removed":{"type":"boolean","enum":[true]}},"required":["removed"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/webhook/deliveries":{"get":{"operationId":"listContainerWebhookDeliveries","tags":["Containers"],"summary":"Read bounded webhook delivery outcomes","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Up to 256 retained deliveries per slot. Includes stable lifecycle event ID, sequence, status, current retry-cycle attempts, manual retries, next/last attempt and HTTP status. Payload, response body, signing secret and provider exceptions are excluded. Delivery is at least once; consumers deduplicate by event ID and order by sequence. Eight automatic attempts use bounded backoff; response timeout is 10 seconds and success is any 2xx. Runtime recovery can cause duplicates. Reads remain available during billing outages.","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"deliveries":{"type":"array","items":{"type":"object","properties":{"id":{"type":"string","format":"uuid"},"sequence":{"type":"integer","exclusiveMinimum":0},"status":{"type":"string","enum":["pending","sending","delivered","exhausted"]},"attempts":{"type":"integer","minimum":0},"manualRetries":{"type":"integer","minimum":0},"nextAt":{"type":["integer","null"]},"retainUntil":{"type":"integer"},"lastAttemptAt":{"type":"integer"},"httpStatus":{"type":["integer","null"]}},"required":["id","sequence","status","attempts","manualRetries","nextAt","retainUntil"]}}},"required":["deliveries"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/webhook/retry":{"post":{"operationId":"retryContainerWebhookDelivery","tags":["Containers"],"summary":"Retry an exhausted owned webhook delivery","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Only retained exhausted deliveries are eligible. Restarts the eight-attempt retry cycle, at most three manual retries per event. The event ID stays stable. Available during billing outages; never starts a guest or renews activity. Cookie mutations require trusted Origin.","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"eventId":{"type":"string","format":"uuid"}},"required":["eventId"],"additionalProperties":false}}}},"responses":{"202":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"id":{"type":"string","format":"uuid"},"sequence":{"type":"integer","exclusiveMinimum":0},"status":{"type":"string","enum":["pending","sending","delivered","exhausted"]},"attempts":{"type":"integer","minimum":0},"manualRetries":{"type":"integer","minimum":0},"nextAt":{"type":["integer","null"]},"retainUntil":{"type":"integer"},"lastAttemptAt":{"type":"integer"},"httpStatus":{"type":["integer","null"]}},"required":["id","sequence","status","attempts","manualRetries","nextAt","retainUntil"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/export":{"get":{"operationId":"exportWorkspaceFiles","tags":["Containers"],"summary":"Download a portable gzip tar archive of /workspace","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Requires owned running generation and paid access. Export is limited to 16777216 compressed bytes and 60 seconds. Quiesce writers first; concurrent writes may fail the export. Mounted filesystems are excluded. Restore a saved workspace before exporting it. Archives preserve file permissions and symlinks; the provider snapshot handle is never exported.","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"}],"responses":{"200":{"description":"Portable workspace backup.","content":{"application/gzip":{"schema":{"type":"string","format":"binary"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"413":{"description":"Request too large.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/workspaces":{"get":{"operationId":"listWorkspaces","tags":["Containers"],"summary":"List account-owned saved filesystem workspaces","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Available when persistence issuance is disabled or billing is unavailable. Metadata only; provider handles remain private. Expired metadata remains for up to 24 hours.","responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"workspaces":{"type":"array","items":{"$ref":"#/components/schemas/Workspace"}},"limits":{"type":["object","null"],"properties":{"maxSaved":{"type":"number"},"maxReservedBytes":{"type":"number"},"retentionMs":{"type":"number"},"maxSavesPerMonth":{"type":"number"}},"required":["maxSaved","maxReservedBytes","retentionMs","maxSavesPerMonth"]},"usage":{"type":"object","properties":{"saved":{"type":"number"},"reservedBytes":{"type":"number"}},"required":["saved","reservedBytes"]}},"required":["workspaces","limits","usage"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"405":{"description":"Method not allowed.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"410":{"description":"Saved workspace has expired.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"413":{"description":"Request too large.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}},"post":{"operationId":"saveWorkspace","tags":["Containers"],"summary":"Snapshot an owned running generation and optionally stop it","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Requires persistence.snapshots and paid access. Idempotency-Key is required; identical retries recover capture receipts for 24 hours. Snapshot commit precedes stop. Immutable full root-filesystem snapshot; no RAM/process state or separately mounted filesystems. Stop:false leaves the source running. Stop:true destroys it only after save. Concurrent guest writes are not application-consistent; quiesce applications before saving. Retention is fixed at save and restores do not extend it. Quotas reserve the source disk capacity, including archived workspaces.","parameters":[{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"},{"schema":{"type":"string","pattern":"^[A-Za-z0-9_-]{1,128}$"},"required":true,"name":"Idempotency-Key","in":"header"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"id":{"type":"string"},"createdAt":{"type":"string","format":"date-time"},"name":{"type":"string","minLength":1,"maxLength":80},"stop":{"type":"boolean"}},"required":["id","createdAt","name"]}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Workspace"}}}},"201":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Workspace"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"405":{"description":"Method not allowed.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"410":{"description":"Saved workspace has expired.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"413":{"description":"Request too large.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/workspaces/{workspaceId}":{"get":{"operationId":"getWorkspace","tags":["Containers"],"summary":"Read owned workspace metadata","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"parameters":[{"schema":{"type":"string","format":"uuid"},"required":true,"name":"workspaceId","in":"path"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Workspace"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"405":{"description":"Method not allowed.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"410":{"description":"Saved workspace has expired.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"413":{"description":"Request too large.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}},"patch":{"operationId":"updateWorkspace","tags":["Containers"],"summary":"Rename or archive an owned workspace","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Archiving prevents restore until unarchived. Does not stop an already restored machine, extend expiry or release storage quota. Does not require active billing.","parameters":[{"schema":{"type":"string","format":"uuid"},"required":true,"name":"workspaceId","in":"path"},{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"name":{"type":"string","minLength":1,"maxLength":80},"archived":{"type":"boolean"}}}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Workspace"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"405":{"description":"Method not allowed.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"410":{"description":"Saved workspace has expired.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"413":{"description":"Request too large.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}},"delete":{"operationId":"deleteWorkspace","tags":["Containers"],"summary":"Revoke future restores and release saved-workspace quota","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Idempotent for 24 hours. Removes the private handle; already admitted restores/running machines continue. Cloudflare has no Worker snapshot deletion primitive; provider data expires according to its TTL, which refreshes on restore. This does not promise immediate physical erasure.","parameters":[{"schema":{"type":"string","format":"uuid"},"required":true,"name":"workspaceId","in":"path"},{"schema":{"type":"string"},"required":false,"name":"Origin","in":"header"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"deleted":{"type":"boolean","enum":[true]}},"required":["deleted"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"405":{"description":"Method not allowed.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"410":{"description":"Saved workspace has expired.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"413":{"description":"Request too large.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/auth/google":{"post":{"operationId":"googleLogin","tags":["Authentication"],"summary":"Sign in with google and create a browser session","requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"credential":{"type":"string"}},"required":["credential"]}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"user":{"$ref":"#/components/schemas/PublicUser"},"created":{"type":"boolean"}},"required":["user","created"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"500":{"description":"Internal error.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/auth/email":{"post":{"operationId":"emailLogin","tags":["Authentication"],"summary":"Sign in with email and create a browser session","description":"Signs in an existing password account or creates an account when the email is unused. New passwords require 8–128 characters. Email is trimmed and lowercased. No verification email is sent. Existing provider-only accounts must use their provider. Limited to 20 attempts per minute per IP.","requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"email":{"type":"string","maxLength":254,"format":"email"},"password":{"type":"string","minLength":1,"maxLength":128}},"required":["email","password"]}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"user":{"$ref":"#/components/schemas/PublicUser"}},"required":["user"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"500":{"description":"Internal error.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/auth/app/google":{"post":{"operationId":"nativeGoogleLogin","tags":["Authentication"],"summary":"Sign in with google for a native app","requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"credential":{"type":"string"}},"required":["credential"]}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/NativeTokens"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"500":{"description":"Internal error.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/auth/app/email":{"post":{"operationId":"nativeEmailLogin","tags":["Authentication"],"summary":"Sign in with email for a native app","requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"email":{"type":"string"},"password":{"type":"string"}},"required":["email","password"]}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/NativeTokens"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"500":{"description":"Internal error.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/auth/app/apple":{"post":{"operationId":"nativeAppleLogin","tags":["Authentication"],"summary":"Sign in with apple for a native app","requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"identity_token":{"type":"string"},"nonce":{"type":"string"},"name":{"type":"string"}},"required":["identity_token","nonce"]}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/NativeTokens"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"500":{"description":"Internal error.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/auth/app/anonymous":{"post":{"operationId":"nativeAnonymousLogin","tags":["Authentication"],"summary":"Create an anonymous native account","responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/NativeTokens"}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/auth/me":{"get":{"operationId":"getBrowserUser","tags":["Authentication"],"summary":"Get the browser session user","description":"Returns user: null when there is no browser session.","security":[{},{"cookieAuth":[]}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"user":{"allOf":[{"$ref":"#/components/schemas/PublicUser"},{"type":["object","null"]}]}},"required":["user"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/auth/logout":{"post":{"operationId":"browserLogout","tags":["Authentication"],"summary":"Revoke the browser session","security":[{"cookieAuth":[]}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"ok":{"type":"boolean"}},"required":["ok"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/auth/app/me":{"get":{"operationId":"getNativeUser","tags":["Authentication"],"summary":"Get the native app user","security":[{"nativeBearer":[]}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"user":{"$ref":"#/components/schemas/PublicUser"}},"required":["user"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}},"delete":{"operationId":"deleteNativeAccount","tags":["Authentication"],"summary":"Delete the native app account","security":[{"nativeBearer":[]}],"description":"Linked providers require fresh provider credentials before deletion.","requestBody":{"required":false,"content":{"application/json":{"schema":{"type":"object","properties":{"google_id_token":{"type":"string"},"google_access_token":{"type":"string"},"apple_identity_token":{"type":"string"},"apple_nonce":{"type":"string"},"apple_authorization_code":{"type":"string"}}}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"deleted":{"type":"boolean"}},"required":["deleted"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"502":{"description":"Provider request failed.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/auth/app/refresh":{"post":{"operationId":"refreshNativeTokens","tags":["Authentication"],"summary":"Rotate native app tokens","requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"refresh_token":{"type":"string"}},"required":["refresh_token"]}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/NativeTokens"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/auth/app/logout":{"post":{"operationId":"nativeLogout","tags":["Authentication"],"summary":"Revoke native app tokens","description":"Revokes the refresh token and, if supplied, the matching Bearer access token.","security":[{},{"nativeBearer":[]}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"refresh_token":{"type":"string"}},"required":["refresh_token"]}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"ok":{"type":"boolean"}},"required":["ok"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/api-keys":{"get":{"operationId":"listAPIKeys","tags":["API Keys"],"summary":"List your API keys without secrets","security":[{"cookieAuth":[]}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"keys":{"type":"array","items":{"type":"object","properties":{"id":{"type":"string"},"name":{"type":"string"},"prefix":{"type":"string"},"created_at":{"type":"string"},"last_used_at":{"type":["string","null"]}},"required":["id","name","prefix","created_at","last_used_at"]}}},"required":["keys"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}},"post":{"operationId":"createAPIKey","tags":["API Keys"],"summary":"Create a named API key","security":[{"cookieAuth":[]}],"description":"Requires a trusted Origin and browser session. Maximum 20 keys. The secret is returned once; it authorizes container, image and SSH operations until revoked, subject to account entitlements.","requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"name":{"type":"string","minLength":1,"maxLength":80}},"required":["name"]}}}},"responses":{"201":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"key":{"type":"object","properties":{"id":{"type":"string"},"name":{"type":"string"},"prefix":{"type":"string"},"created_at":{"type":"string"},"last_used_at":{"type":["string","null"]}},"required":["id","name","prefix","created_at","last_used_at"]},"token":{"type":"string"}},"required":["key","token"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}},"delete":{"operationId":"revokeAPIKey","tags":["API Keys"],"summary":"Revoke an API key","security":[{"cookieAuth":[]}],"description":"Requires a trusted Origin and browser session. Revocation prevents subsequent API requests with this key.","parameters":[{"schema":{"type":"string","minLength":1},"required":true,"name":"id","in":"query"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"ok":{"type":"boolean"}},"required":["ok"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/subscription/config":{"get":{"operationId":"getSubscriptionConfig","tags":["Subscriptions"],"summary":"Get public plans and billing availability","responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"google_client_id":{"type":"string"},"configured":{"type":"boolean"},"plans":{"type":"object","properties":{"builder":{"type":"object","properties":{"name":{"type":"string"},"price":{"type":"number"},"limits":{"type":"object","properties":{"maxComputeUnitHours":{"type":"number"},"maxConcurrentComputeUnits":{"type":"number"},"maxContainers":{"type":"number"},"maxStartsPerMonth":{"type":"number"},"maxSessionMs":{"type":"number"},"idleTimeoutMs":{"type":"number"}},"required":["maxComputeUnitHours","maxConcurrentComputeUnits","maxContainers","maxStartsPerMonth","maxSessionMs","idleTimeoutMs"]},"machine":{"type":"object","properties":{"instance":{"type":"string"},"cpuVcpu":{"type":"number"},"memoryMiB":{"type":"number"},"diskGB":{"type":"number"}},"required":["instance","cpuVcpu","memoryMiB","diskGB"]},"sizes":{"type":"array","items":{"type":"object","properties":{"id":{"type":"string","enum":["lite","small","medium","large","xl"]},"name":{"type":"string"},"instance":{"type":"string"},"cpuVcpu":{"type":"number"},"memoryMiB":{"type":"number"},"diskGB":{"type":"number"},"computeUnits":{"type":"number"}},"required":["id","name","instance","cpuVcpu","memoryMiB","diskGB","computeUnits"]}},"access":{"type":"object","properties":{"maxTerminalConnections":{"type":"number"},"maxSSHAccessTokens":{"type":"number"},"sshTokenLifetimeMs":{"type":"number"}},"required":["maxTerminalConnections","maxSSHAccessTokens","sshTokenLifetimeMs"]},"features":{"type":"object","additionalProperties":{"type":"boolean"}}},"required":["name","price","limits","machine","sizes","access","features"]},"pro":{"type":"object","properties":{"name":{"type":"string"},"price":{"type":"number"},"limits":{"type":"object","properties":{"maxComputeUnitHours":{"type":"number"},"maxConcurrentComputeUnits":{"type":"number"},"maxContainers":{"type":"number"},"maxStartsPerMonth":{"type":"number"},"maxSessionMs":{"type":"number"},"idleTimeoutMs":{"type":"number"}},"required":["maxComputeUnitHours","maxConcurrentComputeUnits","maxContainers","maxStartsPerMonth","maxSessionMs","idleTimeoutMs"]},"machine":{"type":"object","properties":{"instance":{"type":"string"},"cpuVcpu":{"type":"number"},"memoryMiB":{"type":"number"},"diskGB":{"type":"number"}},"required":["instance","cpuVcpu","memoryMiB","diskGB"]},"sizes":{"type":"array","items":{"type":"object","properties":{"id":{"type":"string","enum":["lite","small","medium","large","xl"]},"name":{"type":"string"},"instance":{"type":"string"},"cpuVcpu":{"type":"number"},"memoryMiB":{"type":"number"},"diskGB":{"type":"number"},"computeUnits":{"type":"number"}},"required":["id","name","instance","cpuVcpu","memoryMiB","diskGB","computeUnits"]}},"access":{"type":"object","properties":{"maxTerminalConnections":{"type":"number"},"maxSSHAccessTokens":{"type":"number"},"sshTokenLifetimeMs":{"type":"number"}},"required":["maxTerminalConnections","maxSSHAccessTokens","sshTokenLifetimeMs"]},"features":{"type":"object","additionalProperties":{"type":"boolean"}}},"required":["name","price","limits","machine","sizes","access","features"]},"scale":{"type":"object","properties":{"name":{"type":"string"},"price":{"type":"number"},"limits":{"type":"object","properties":{"maxComputeUnitHours":{"type":"number"},"maxConcurrentComputeUnits":{"type":"number"},"maxContainers":{"type":"number"},"maxStartsPerMonth":{"type":"number"},"maxSessionMs":{"type":"number"},"idleTimeoutMs":{"type":"number"}},"required":["maxComputeUnitHours","maxConcurrentComputeUnits","maxContainers","maxStartsPerMonth","maxSessionMs","idleTimeoutMs"]},"machine":{"type":"object","properties":{"instance":{"type":"string"},"cpuVcpu":{"type":"number"},"memoryMiB":{"type":"number"},"diskGB":{"type":"number"}},"required":["instance","cpuVcpu","memoryMiB","diskGB"]},"sizes":{"type":"array","items":{"type":"object","properties":{"id":{"type":"string","enum":["lite","small","medium","large","xl"]},"name":{"type":"string"},"instance":{"type":"string"},"cpuVcpu":{"type":"number"},"memoryMiB":{"type":"number"},"diskGB":{"type":"number"},"computeUnits":{"type":"number"}},"required":["id","name","instance","cpuVcpu","memoryMiB","diskGB","computeUnits"]}},"access":{"type":"object","properties":{"maxTerminalConnections":{"type":"number"},"maxSSHAccessTokens":{"type":"number"},"sshTokenLifetimeMs":{"type":"number"}},"required":["maxTerminalConnections","maxSSHAccessTokens","sshTokenLifetimeMs"]},"features":{"type":"object","additionalProperties":{"type":"boolean"}}},"required":["name","price","limits","machine","sizes","access","features"]}}}},"required":["configured","plans"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/subscription":{"get":{"operationId":"getSubscription","tags":["Subscriptions"],"summary":"Get subscription and paid entitlement","security":[{"cookieAuth":[]}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SubscriptionState"}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/subscription/trial":{"post":{"operationId":"redeemTrialCoupon","tags":["Subscriptions"],"summary":"Redeem a card-free trial coupon; one trial per account","security":[{"cookieAuth":[]}],"description":"Requires a browser session cookie and trusted Origin. Bearer automation credentials do not authorize billing mutations.","parameters":[{"schema":{"type":"string"},"required":true,"name":"Origin","in":"header"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"plan":{"type":"string","enum":["builder","pro","scale"]},"code":{"type":"string","minLength":4,"maxLength":64}},"required":["plan","code"]}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SubscriptionState"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/subscription/checkout":{"post":{"operationId":"createCheckout","tags":["Subscriptions"],"summary":"Create or reuse embedded checkout","security":[{"cookieAuth":[]}],"description":"Requires a browser session cookie and trusted Origin. Bearer automation credentials do not authorize billing mutations.","parameters":[{"schema":{"type":"string"},"required":true,"name":"Origin","in":"header"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"plan":{"type":"string","enum":["builder","pro","scale"]}},"required":["plan"]}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"client_secret":{"type":"string"},"publishable_key":{"type":"string"}},"required":["client_secret","publishable_key"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/subscription/complete":{"post":{"operationId":"completeCheckout","tags":["Subscriptions"],"summary":"Verify owned checkout and paid entitlement","security":[{"cookieAuth":[]}],"description":"Requires a browser session cookie and trusted Origin. Bearer automation credentials do not authorize billing mutations.","parameters":[{"schema":{"type":"string"},"required":true,"name":"Origin","in":"header"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"session_id":{"type":"string"}},"required":["session_id"]}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SubscriptionState"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/subscription/portal":{"post":{"operationId":"createBillingPortal","tags":["Subscriptions"],"summary":"Open billing portal or confirm an upgrade","security":[{"cookieAuth":[]}],"description":"Requires a browser session cookie and trusted Origin. Bearer automation credentials do not authorize billing mutations.","parameters":[{"schema":{"type":"string"},"required":true,"name":"Origin","in":"header"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"plan":{"type":"string","enum":["builder","pro","scale"]}}}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"url":{"type":"string"}},"required":["url"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/subscription/change":{"post":{"operationId":"changeSubscription","tags":["Subscriptions"],"summary":"Schedule a downgrade or remove a scheduled downgrade","security":[{"cookieAuth":[]}],"description":"Requires a browser session cookie and trusted Origin. Bearer automation credentials do not authorize billing mutations.","parameters":[{"schema":{"type":"string"},"required":true,"name":"Origin","in":"header"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"plan":{"type":"string","enum":["builder","pro","scale"]},"confirm":{"type":"boolean","enum":[true]}},"required":["plan","confirm"]}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SubscriptionState"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/subscription/cancel":{"post":{"operationId":"cancelSubscription","tags":["Subscriptions"],"summary":"Cancel at the end of the paid period","security":[{"cookieAuth":[]}],"description":"Requires a browser session cookie and trusted Origin. Bearer automation credentials do not authorize billing mutations.","parameters":[{"schema":{"type":"string"},"required":true,"name":"Origin","in":"header"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"confirm":{"type":"boolean","enum":[true]}},"required":["confirm"]}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SubscriptionState"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/subscription/resume":{"post":{"operationId":"resumeSubscription","tags":["Subscriptions"],"summary":"Resume a subscription pending cancellation","security":[{"cookieAuth":[]}],"description":"Requires a browser session cookie and trusted Origin. Bearer automation credentials do not authorize billing mutations.","parameters":[{"schema":{"type":"string"},"required":true,"name":"Origin","in":"header"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{}}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SubscriptionState"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/subscription/webhook":{"post":{"operationId":"stripeWebhook","tags":["Internal"],"summary":"Reconcile signed Stripe billing events","security":[{"stripeSignature":[]}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"id":{"type":"string"},"type":{"type":"string"},"data":{"type":"object","properties":{"object":{"type":"object","additionalProperties":{}}},"required":["object"]}},"required":["id","type","data"],"additionalProperties":{}}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"received":{"type":"boolean"}},"required":["received"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers":{"get":{"operationId":"getContainers","tags":["Containers"],"summary":"Get account containers, paid allowance, and usage","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"parameters":[{"schema":{"type":"string"},"required":false,"name":"id","in":"query"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ContainerStatus"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}},"post":{"operationId":"startContainer","tags":["Containers"],"summary":"Reserve a start and boot a container","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Requires paid access. workspaceId restores an owned, unarchived saved filesystem workspace using its original image, size and internet policy; cannot combine with imageId/catalogId. Requires persistence.snapshots. Expired snapshots return 410, incompatible image versions return 409 before start reservation. A restore consumes a normal start and compute allowance. New generation invalidates old access; RAM and processes are not restored. No empty-image fallback. Body is optional; size defaults to lite and accepts lite, small, medium, large, xl. Runtime is reserved against the shared monthly compute allowance before boot; unused reserved runtime is released on stop. Sessions also end at the UTC month boundary. imageId and catalogId are mutually exclusive. Optional Idempotency-Key (1–128 letters, digits, underscores or hyphens) resolves retries to one account-scoped reservation for 24 hours. Keyed responses include creation identity and current starting/running status. internet defaults to true. internet:false requires networking.internetControl and a compatible private runtime; otherwise fails closed with 503 network_policy_unavailable before reserving a start. Changed image, size or internet selection returns 409 idempotency_key_conflict; stopped/replaced reservations return 409 creation_no_longer_running. Unkeyed requests reserve a new start. Cookie requests require a trusted Origin.","parameters":[{"schema":{"type":"string","description":"Trusted browser origin; required for cookie mutations."},"required":false,"description":"Trusted browser origin; required for cookie mutations.","name":"Origin","in":"header"},{"schema":{"type":"string","pattern":"^[A-Za-z0-9_-]{1,128}$"},"required":false,"name":"Idempotency-Key","in":"header"}],"requestBody":{"required":false,"content":{"application/json":{"schema":{"type":"object","properties":{"imageId":{"type":"string"},"catalogId":{"type":"string"},"size":{"type":"string","enum":["lite","small","medium","large","xl"]},"internet":{"type":"boolean"},"workspaceId":{"type":"string","format":"uuid"}}}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"allOf":[{"$ref":"#/components/schemas/ContainerStatus"},{"type":"object","properties":{"creation":{"type":"object","properties":{"id":{"type":"string"},"containerId":{"type":"string"},"createdAt":{"type":"string"},"status":{"type":"string","enum":["starting","running"]}},"required":["id","containerId","createdAt","status"]}}}]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Capacity, image selection, idempotency conflict, or original creation no longer running.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"creation":{"type":"object","properties":{"id":{"type":"string"},"containerId":{"type":"string"},"status":{"type":"string","enum":["stopped"]}},"required":["id","containerId","status"]}},"required":["error"]}}}},"410":{"description":"Saved workspace has expired.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}},"delete":{"operationId":"stopContainer","tags":["Containers"],"summary":"Stop a selected account container","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"An ID is required when multiple containers exist. createdAt rejects stale actions. Cookie requests require a trusted Origin. Cleanup remains available during billing outages.","parameters":[{"schema":{"type":"string"},"required":false,"name":"id","in":"query"},{"schema":{"type":"string"},"required":false,"name":"createdAt","in":"query"},{"schema":{"type":"string","description":"Trusted browser origin; required for cookie mutations."},"required":false,"description":"Trusted browser origin; required for cookie mutations.","name":"Origin","in":"header"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ContainerStatus"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/ssh":{"post":{"operationId":"issueSSHAccess","tags":["Containers"],"summary":"Issue short-lived SSH access to a running container","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Returns a secret-bearing command. Cookie requests require a trusted Origin. expiresAt is Unix milliseconds.","parameters":[{"schema":{"type":"string","description":"Trusted browser origin; required for cookie mutations."},"required":false,"description":"Trusted browser origin; required for cookie mutations.","name":"Origin","in":"header"}],"requestBody":{"required":false,"content":{"application/json":{"schema":{"type":"object","properties":{"id":{"type":"string"},"createdAt":{"type":"string"}},"required":["id"]}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"command":{"type":"string"},"expiresAt":{"type":"number"},"hostname":{"type":"string"}},"required":["command","expiresAt","hostname"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/terminal":{"get":{"operationId":"connectBrowserTerminal","tags":["Containers"],"summary":"Upgrade to a browser terminal WebSocket","security":[{"cookieAuth":[]}],"parameters":[{"schema":{"type":"string"},"required":false,"name":"id","in":"query"},{"schema":{"type":"string"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"integer"},"required":false,"name":"cols","in":"query"},{"schema":{"type":"integer"},"required":false,"name":"rows","in":"query"},{"schema":{"type":"string"},"required":true,"name":"Origin","in":"header"},{"schema":{"type":"string","enum":["websocket"]},"required":true,"name":"Upgrade","in":"header"}],"responses":{"101":{"description":"Terminal WebSocket established."},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"426":{"description":"WebSocket upgrade required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/ssh/validate":{"post":{"operationId":"validateSSHAccess","tags":["Internal"],"summary":"Validate SSH access for the trusted gateway","security":[{"sshGateway":[]}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"token":{"type":"string"}},"required":["token"]}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"expiresAt":{"type":"number"}},"required":["expiresAt"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/ssh/connect":{"get":{"operationId":"connectSSHGateway","tags":["Internal"],"summary":"Upgrade the trusted SSH gateway connection","security":[{"sshGateway":[]}],"parameters":[{"schema":{"type":"string"},"required":true,"name":"x-mainbrella-ssh-token","in":"header"},{"schema":{"type":"string","enum":["websocket"]},"required":true,"name":"Upgrade","in":"header"}],"responses":{"101":{"description":"SSH WebSocket established; query parameters are not accepted."},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/exec":{"post":{"operationId":"executeContainerCommand","tags":["Containers"],"summary":"Run a bounded foreground shell command","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Runs /bin/sh -lc without a PTY on an owned running generation. Does not create a machine or reserve a start. Command is limited to 16384 UTF-8 bytes; request body to 32 KiB. Combined stdout/stderr is limited to 1 MiB. Timeout includes process startup and is capped by the hard deadline. Timeout or excess output terminates the process and returns partial output with a null exitCode. A disconnect requests cancellation when observable; the timeout always bounds the request. Results are not retained and commands are not idempotent: do not blindly retry after transport failure. Cookie requests require a trusted Origin.","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string","description":"Trusted browser origin; required for cookie mutations."},"required":false,"description":"Trusted browser origin; required for cookie mutations.","name":"Origin","in":"header"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"command":{"type":"string","minLength":1,"maxLength":16384,"description":"Shell command, at most 16 KiB in UTF-8."},"timeoutMs":{"type":"integer","minimum":1,"maximum":60000,"default":30000}},"required":["command"],"additionalProperties":false}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"stdout":{"type":"string"},"stderr":{"type":"string"},"exitCode":{"type":["integer","null"]},"timedOut":{"type":"boolean"},"outputTruncated":{"type":"boolean"}},"required":["stdout","stderr","exitCode","timedOut","outputTruncated"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"413":{"description":"Request too large.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/files":{"get":{"operationId":"readContainerFile","tags":["Containers"],"summary":"Read a binary file","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Accesses files in an owned running generation without SSH. Does not create a machine or consume a start. Files are limited to 1048576 bytes; oversized reads return an error without partial data. Runtime operations are bounded by 30000 ms and the hard deadline, share the four-command execution pool, and renew idle activity. Files remain ephemeral. Custom images need /bin/sh and GNU coreutils. Cookie writes require a trusted Origin. Reads regular files, including symlink targets inside the guest. Returns raw application/octet-stream bytes with caching disabled.","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string","minLength":2,"maxLength":4096,"description":"Absolute guest file path, at most 4096 UTF-8 bytes. Empty, dot and parent segments are rejected."},"required":true,"description":"Absolute guest file path, at most 4096 UTF-8 bytes. Empty, dot and parent segments are rejected.","name":"path","in":"query"},{"schema":{"type":"string","description":"Trusted browser origin; required for cookie writes."},"required":false,"description":"Trusted browser origin; required for cookie writes.","name":"Origin","in":"header"}],"responses":{"200":{"description":"Raw file bytes.","content":{"application/octet-stream":{"schema":{"type":"string","format":"binary"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"413":{"description":"Request too large.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}},"put":{"operationId":"writeContainerFile","tags":["Containers"],"summary":"Write a binary file","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Accesses files in an owned running generation without SSH. Does not create a machine or consume a start. Files are limited to 1048576 bytes; oversized reads return an error without partial data. Runtime operations are bounded by 30000 ms and the hard deadline, share the four-command execution pool, and renew idle activity. Files remain ephemeral. Custom images need /bin/sh and GNU coreutils. Cookie writes require a trusted Origin. The body is raw bytes; an empty body writes an empty file. The parent directory must exist. Writes use a temporary file and atomic rename; regular files are replaced, while directories and existing symlinks are rejected. New files use mode 0600; replacement preserves permission bits. A lost response may hide a successful write: read to reconcile before retrying.","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string","minLength":2,"maxLength":4096,"description":"Absolute guest file path, at most 4096 UTF-8 bytes. Empty, dot and parent segments are rejected."},"required":true,"description":"Absolute guest file path, at most 4096 UTF-8 bytes. Empty, dot and parent segments are rejected.","name":"path","in":"query"},{"schema":{"type":"string","description":"Trusted browser origin; required for cookie writes."},"required":false,"description":"Trusted browser origin; required for cookie writes.","name":"Origin","in":"header"}],"requestBody":{"required":false,"content":{"application/octet-stream":{"schema":{"type":"string","format":"binary"}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"path":{"type":"string"},"size":{"type":"integer","minimum":0,"maximum":1048576}},"required":["path","size"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"413":{"description":"Request too large.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/files/list":{"get":{"tags":["Containers"],"security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Owned, generation-qualified guest filesystem operation. Rechecks the generation and paid lease before launch, shares the four-operation execution pool and renews idle activity. Bounded by 30000 ms and the hard deadline; output is at most 1048576 bytes. Requires bash, GNU coreutils, findutils and sed in the image. Intermediate symlinks resolve inside the owned guest. No start is consumed. Files are ephemeral. Mutations are never automatically retried; inspect state after a lost response. One level only, sorted by UTF-8 filename bytes. Child symlinks are not followed. The directory itself may be a symlink. Pagination rescans the directory; changes between pages can duplicate or omit entries. Non-UTF-8 filenames fail explicitly rather than returning an unusable replacement path.","operationId":"listContainerDirectory","summary":"List a directory page","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string","minLength":1,"maxLength":4096,"description":"Absolute UTF-8 guest path, at most 4096 bytes. No empty, dot or parent segments. Root is allowed only for list/stat."},"required":true,"description":"Absolute UTF-8 guest path, at most 4096 bytes. No empty, dot or parent segments. Root is allowed only for list/stat.","name":"path","in":"query"},{"schema":{"type":"integer","minimum":1,"maximum":1000,"default":100},"required":false,"name":"limit","in":"query"},{"schema":{"type":["integer","null"],"minimum":0,"maximum":1000000,"default":0},"required":false,"name":"offset","in":"query"},{"schema":{"type":"string","description":"Required for cookie mutations; Bearer keys may omit it."},"required":false,"description":"Required for cookie mutations; Bearer keys may omit it.","name":"Origin","in":"header"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"path":{"type":"string"},"entries":{"type":"array","items":{"$ref":"#/components/schemas/FileEntry"}},"nextOffset":{"type":["integer","null"]}},"required":["path","entries","nextOffset"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"413":{"description":"Request too large.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/files/stat":{"get":{"tags":["Containers"],"security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Owned, generation-qualified guest filesystem operation. Rechecks the generation and paid lease before launch, shares the four-operation execution pool and renews idle activity. Bounded by 30000 ms and the hard deadline; output is at most 1048576 bytes. Requires bash, GNU coreutils, findutils and sed in the image. Intermediate symlinks resolve inside the owned guest. No start is consumed. Files are ephemeral. Mutations are never automatically retried; inspect state after a lost response. Returns metadata for the symlink itself by default, including its target; followSymlinks=true reads the target instead. Broken symlinks can be inspected without dereferencing. Modification times have second precision.","operationId":"statContainerFile","summary":"Read file metadata","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string","minLength":1,"maxLength":4096,"description":"Absolute UTF-8 guest path, at most 4096 bytes. No empty, dot or parent segments. Root is allowed only for list/stat."},"required":true,"description":"Absolute UTF-8 guest path, at most 4096 bytes. No empty, dot or parent segments. Root is allowed only for list/stat.","name":"path","in":"query"},{"schema":{"type":"string","enum":["true","false"]},"required":false,"name":"followSymlinks","in":"query"},{"schema":{"type":"string","description":"Required for cookie mutations; Bearer keys may omit it."},"required":false,"description":"Required for cookie mutations; Bearer keys may omit it.","name":"Origin","in":"header"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/FileEntry"}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"413":{"description":"Request too large.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/files/mkdir":{"post":{"tags":["Containers"],"security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Owned, generation-qualified guest filesystem operation. Rechecks the generation and paid lease before launch, shares the four-operation execution pool and renews idle activity. Bounded by 30000 ms and the hard deadline; output is at most 1048576 bytes. Requires bash, GNU coreutils, findutils and sed in the image. Intermediate symlinks resolve inside the owned guest. No start is consumed. Files are ephemeral. Mutations are never automatically retried; inspect state after a lost response. recursive=true creates missing parents; existing non-symlink directories succeed. Default permissions are 0700 for the final directory. Parent permissions follow the guest umask. Existing leaf symlinks and non-directories conflict.","operationId":"createContainerDirectory","summary":"Create a directory","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string","description":"Required for cookie mutations; Bearer keys may omit it."},"required":false,"description":"Required for cookie mutations; Bearer keys may omit it.","name":"Origin","in":"header"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"path":{"type":"string","minLength":1,"maxLength":4096,"description":"Absolute UTF-8 guest path, at most 4096 bytes. No empty, dot or parent segments. Root is allowed only for list/stat."},"recursive":{"type":"boolean"},"mode":{"type":"string","pattern":"^0[0-7]{3}$","description":"Octal permission bits, from 0000 through 0777."}},"required":["path"],"additionalProperties":false}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"path":{"type":"string"},"ok":{"type":"boolean","enum":[true]}},"required":["path","ok"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"413":{"description":"Request too large.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/files/remove":{"delete":{"tags":["Containers"],"security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Owned, generation-qualified guest filesystem operation. Rechecks the generation and paid lease before launch, shares the four-operation execution pool and renews idle activity. Bounded by 30000 ms and the hard deadline; output is at most 1048576 bytes. Requires bash, GNU coreutils, findutils and sed in the image. Intermediate symlinks resolve inside the owned guest. No start is consumed. Files are ephemeral. Mutations are never automatically retried; inspect state after a lost response. Removes a symlink itself without following its target. Directories must be empty unless recursive=true. Missing paths return 404. Recursive deletion may partially complete before interruption. Root cannot be removed.","operationId":"removeContainerFile","summary":"Remove a file or directory","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string","minLength":1,"maxLength":4096,"description":"Absolute UTF-8 guest path, at most 4096 bytes. No empty, dot or parent segments. Root is allowed only for list/stat."},"required":true,"description":"Absolute UTF-8 guest path, at most 4096 bytes. No empty, dot or parent segments. Root is allowed only for list/stat.","name":"path","in":"query"},{"schema":{"type":"string","enum":["true","false"]},"required":false,"name":"recursive","in":"query"},{"schema":{"type":"string","description":"Required for cookie mutations; Bearer keys may omit it."},"required":false,"description":"Required for cookie mutations; Bearer keys may omit it.","name":"Origin","in":"header"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"path":{"type":"string"},"ok":{"type":"boolean","enum":[true]}},"required":["path","ok"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"413":{"description":"Request too large.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/files/move":{"post":{"tags":["Containers"],"security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Owned, generation-qualified guest filesystem operation. Rechecks the generation and paid lease before launch, shares the four-operation execution pool and renews idle activity. Bounded by 30000 ms and the hard deadline; output is at most 1048576 bytes. Requires bash, GNU coreutils, findutils and sed in the image. Intermediate symlinks resolve inside the owned guest. No start is consumed. Files are ephemeral. Mutations are never automatically retried; inspect state after a lost response. Destination must be unused and its parent must exist; no replacement or directory nesting is performed. Moves preserve symlinks. Across filesystems the guest may copy then remove, so interruption can leave both paths. Root and moves into the source subtree are rejected.","operationId":"moveContainerFile","summary":"Move a file or directory","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string","description":"Required for cookie mutations; Bearer keys may omit it."},"required":false,"description":"Required for cookie mutations; Bearer keys may omit it.","name":"Origin","in":"header"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"path":{"type":"string","minLength":1,"maxLength":4096,"description":"Absolute UTF-8 guest path, at most 4096 bytes. No empty, dot or parent segments. Root is allowed only for list/stat."},"destination":{"type":"string","minLength":1,"maxLength":4096,"description":"Absolute UTF-8 guest path, at most 4096 bytes. No empty, dot or parent segments. Root is allowed only for list/stat."}},"required":["path","destination"],"additionalProperties":false}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"path":{"type":"string"},"destination":{"type":"string"},"ok":{"type":"boolean","enum":[true]}},"required":["path","destination","ok"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"413":{"description":"Request too large.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/containers/files/chmod":{"patch":{"tags":["Containers"],"security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Owned, generation-qualified guest filesystem operation. Rechecks the generation and paid lease before launch, shares the four-operation execution pool and renews idle activity. Bounded by 30000 ms and the hard deadline; output is at most 1048576 bytes. Requires bash, GNU coreutils, findutils and sed in the image. Intermediate symlinks resolve inside the owned guest. No start is consumed. Files are ephemeral. Mutations are never automatically retried; inspect state after a lost response. Changes the selected entry's permission bits. Leaf symlinks are rejected. No recursive chmod, owner changes or special mode bits. Root cannot be modified.","operationId":"setContainerFileMode","summary":"Set file permission bits","parameters":[{"schema":{"type":"string"},"required":true,"name":"id","in":"query"},{"schema":{"type":"string","format":"date-time"},"required":true,"name":"createdAt","in":"query"},{"schema":{"type":"string","minLength":1,"maxLength":4096,"description":"Absolute UTF-8 guest path, at most 4096 bytes. No empty, dot or parent segments. Root is allowed only for list/stat."},"required":true,"description":"Absolute UTF-8 guest path, at most 4096 bytes. No empty, dot or parent segments. Root is allowed only for list/stat.","name":"path","in":"query"},{"schema":{"type":"string","description":"Required for cookie mutations; Bearer keys may omit it."},"required":false,"description":"Required for cookie mutations; Bearer keys may omit it.","name":"Origin","in":"header"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"mode":{"type":"string","pattern":"^0[0-7]{3}$","description":"Octal permission bits, from 0000 through 0777."}},"required":["mode"],"additionalProperties":false}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"path":{"type":"string"},"mode":{"type":"string","pattern":"^0[0-7]{3}$","description":"Octal permission bits, from 0000 through 0777."},"ok":{"type":"boolean","enum":[true]}},"required":["path","mode","ok"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"402":{"description":"Paid access required.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"413":{"description":"Request too large.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/images":{"get":{"operationId":"listImages","tags":["Images"],"summary":"List account images and monthly build usage","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"images":{"type":"array","items":{"$ref":"#/components/schemas/Image"}},"buildsEnabled":{"type":"boolean"},"limits":{"type":"object","properties":{"maxBuildsPerMonth":{"type":"number"},"maxSavedImages":{"type":"number"},"maxContextBytes":{"type":"number"},"maxDockerfileBytes":{"type":"number"},"maxBuildSeconds":{"type":"number"}},"required":["maxBuildsPerMonth","maxSavedImages","maxContextBytes","maxDockerfileBytes","maxBuildSeconds"]},"usage":{"type":"object","properties":{"month":{"type":"string"},"builds":{"type":"number"}},"required":["month","builds"]}},"required":["images","buildsEnabled","limits","usage"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}},"post":{"operationId":"createImage","tags":["Images"],"summary":"Queue a custom image build","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Cookie requests require a trusted Origin. Dockerfile must start with FROM mainbrella:base; one build stage. Optional gzip context is limited to 512 KiB, Dockerfile to 16 KiB.","requestBody":{"required":true,"content":{"multipart/form-data":{"schema":{"type":"object","properties":{"name":{"type":"string","minLength":1,"maxLength":80},"dockerfile":{"type":"string"},"context":{"type":"string","format":"binary"}},"required":["name","dockerfile"]}}}},"responses":{"202":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"image":{"$ref":"#/components/schemas/Image"}},"required":["image"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"413":{"description":"Request too large.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"429":{"description":"Rate, quota, or connection limit exceeded.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/images/{id}":{"get":{"operationId":"getImage","tags":["Images"],"summary":"Get an owned image","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"parameters":[{"schema":{"type":"string","format":"uuid"},"required":true,"name":"id","in":"path"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"image":{"$ref":"#/components/schemas/Image"}},"required":["image"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}},"delete":{"operationId":"deleteImage","tags":["Images"],"summary":"Delete an owned image and queue deployment reconciliation","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"description":"Active builds cannot be deleted. Cookie requests require a trusted Origin.","parameters":[{"schema":{"type":"string","format":"uuid"},"required":true,"name":"id","in":"path"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"deleted":{"type":"boolean"}},"required":["deleted"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/images/{id}/logs":{"get":{"operationId":"getImageLogs","tags":["Images"],"summary":"Get image build logs","security":[{"cookieAuth":[]},{"sessionBearer":[]},{"apiKeyBearer":[]}],"parameters":[{"schema":{"type":"string","format":"uuid"},"required":true,"name":"id","in":"path"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"logs":{"type":"string"},"status":{"type":"string"}},"required":["logs","status"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"403":{"description":"Origin or permission denied.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/internal/image-builds/manifest":{"get":{"operationId":"getImageManifest","tags":["Internal"],"summary":"Get deployable custom images","security":[{"imageBuild":[]}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"images":{"type":"object","additionalProperties":{"type":"object","properties":{"image":{"type":"string"}},"required":["image"]}}},"required":["images"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/internal/image-builds/deployment-lock":{"post":{"operationId":"acquireImageDeploymentLock","tags":["Internal"],"summary":"Acquire the image deployment lease","security":[{"imageBuild":[]}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"token":{"type":"string","format":"uuid"}},"required":["token"]}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"acquired":{"type":"boolean"}},"required":["acquired"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}},"delete":{"operationId":"releaseImageDeploymentLock","tags":["Internal"],"summary":"Release the image deployment lease","security":[{"imageBuild":[]}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"token":{"type":"string","format":"uuid"}},"required":["token"]}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"released":{"type":"boolean"}},"required":["released"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/internal/image-builds/{id}/source":{"post":{"operationId":"claimImageBuildSource","tags":["Internal"],"summary":"Claim queued build source for a trusted runner","security":[{"imageBuild":[]}],"parameters":[{"schema":{"type":"string","format":"uuid"},"required":true,"name":"id","in":"path"}],"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"dockerfile":{"type":"string"},"contextBase64":{"type":["string","null"]}},"required":["dockerfile","contextBase64"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}},"/internal/image-builds/{id}/status":{"post":{"operationId":"updateImageBuildStatus","tags":["Internal"],"summary":"Report trusted image publication or build failure","security":[{"imageBuild":[]}],"parameters":[{"schema":{"type":"string","format":"uuid"},"required":true,"name":"id","in":"path"}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"status":{"type":"string","enum":["failed","publishing","ready"]},"image":{"type":"string"},"logs":{"type":"string"}},"required":["status"]}}}},"responses":{"200":{"description":"Successful response.","content":{"application/json":{"schema":{"type":"object","properties":{"updated":{"type":"boolean"}},"required":["updated"]}}}},"400":{"description":"Invalid request.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"401":{"description":"Authentication required or credential invalid.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"404":{"description":"Not found.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"409":{"description":"Conflicts with current state.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}},"503":{"description":"Service unavailable.","content":{"application/json":{"schema":{"type":"object","properties":{"error":{"type":"string"},"provider":{"type":"string"}},"required":["error"]}}}}}}}},"webhooks":{}}