Applications ¶
applications¶
POST /api/v1/applications¶
Create Application
Description
Create a private application for devevelopment purposes.
This endpoint creates private applications suitable for development and testing. The app starts private. To let other people connect, use the web interface where additional metadata (description, image, privacy policy) can be provided.
When a page slug is provided, the page URL is automatically added to the redirect URIs. If no explicit redirect URIs are provided, localhost is also added to allow local development.
Input parameters
| Parameter | In | Type | Default | Nullable | Description |
|---|---|---|---|---|---|
HTTPBearer |
header | string | N/A | No | JWT Bearer token |
refreshed-token |
header | No | |||
token |
cookie | string | No |
Request body
{
"name": "string",
"description": null,
"redirect_uris": null,
"page": null,
"generate_secret": true
}
Schema of the request body
{
"properties": {
"name": {
"type": "string",
"maxLength": 100,
"minLength": 1,
"title": "Name"
},
"description": {
"anyOf": [
{
"type": "string",
"maxLength": 500
},
{
"type": "null"
}
],
"title": "Description"
},
"redirect_uris": {
"anyOf": [
{
"items": {
"type": "string"
},
"type": "array"
},
{
"type": "null"
}
],
"title": "Redirect Uris"
},
"page": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"title": "Page"
},
"generate_secret": {
"type": "boolean",
"title": "Generate Secret",
"default": false
}
},
"type": "object",
"required": [
"name"
],
"title": "ApplicationCreate",
"description": "Create a private application.\n\nThis endpoint creates private applications suitable for development and testing.\nThe app starts private. To let other people connect,\nuse the web interface where additional metadata (description, image, privacy policy)\ncan be provided."
}
Responses
{
"id": "string",
"name": "string",
"description": null,
"image": null,
"url": null,
"redirect_uris": null,
"privacy_statement": null,
"brand_color": null,
"published": true,
"webhook_endpoints": null,
"webhook_secret": null,
"client_secret": null,
"page": null,
"is_private": true,
"is_clientside_app": true
}
Schema of the response body
{
"properties": {
"id": {
"type": "string",
"title": "Id"
},
"name": {
"type": "string",
"title": "Name"
},
"description": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"title": "Description"
},
"image": {
"anyOf": [
{
"type": "string",
"minLength": 1,
"format": "uri"
},
{
"type": "null"
}
],
"title": "Image"
},
"url": {
"anyOf": [
{
"type": "string",
"minLength": 1,
"format": "uri"
},
{
"type": "null"
}
],
"title": "Url"
},
"redirect_uris": {
"anyOf": [
{
"items": {
"type": "string"
},
"type": "array"
},
{
"type": "null"
}
],
"title": "Redirect Uris"
},
"privacy_statement": {
"anyOf": [
{
"type": "string",
"minLength": 1,
"format": "uri"
},
{
"type": "null"
}
],
"title": "Privacy Statement"
},
"brand_color": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"title": "Brand Color"
},
"published": {
"type": "boolean",
"title": "Published",
"description": "The App Directory is retired. Reflects the last stored listing; removed on 2026-10-12.",
"default": false,
"deprecated": true
},
"webhook_endpoints": {
"anyOf": [
{
"items": {
"type": "string",
"minLength": 1,
"format": "uri"
},
"type": "array"
},
{
"type": "null"
}
],
"title": "Webhook Endpoints"
},
"webhook_secret": {
"anyOf": [
{
"type": "string",
"format": "password",
"writeOnly": true
},
{
"type": "null"
}
],
"title": "Webhook Secret"
},
"client_secret": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"title": "Client Secret"
},
"page": {
"anyOf": [
{
"$ref": "#/components/schemas/PageResponse"
},
{
"type": "null"
}
]
},
"is_private": {
"type": "boolean",
"title": "Is Private",
"description": "An application is private if it is missing any of: description, URL, image, or privacy statement.",
"readOnly": true
},
"is_clientside_app": {
"type": "boolean",
"title": "Is Clientside App",
"description": "Check if this is a client-side app based on privacy policy URL.\n\nApps that went live through the Pages one-click path have privacy_statement set to\nthe standard client-side privacy policy URL: that is their attestation.",
"readOnly": true
}
},
"type": "object",
"required": [
"id",
"name",
"is_private",
"is_clientside_app"
],
"title": "ApplicationCreateResponse",
"description": "Response for created application."
}
{
"detail": [
{
"loc": [
null
],
"msg": "string",
"type": "string"
}
]
}
Schema of the response body
{
"properties": {
"detail": {
"items": {
"$ref": "#/components/schemas/ValidationError"
},
"type": "array",
"title": "Detail"
}
},
"type": "object",
"title": "HTTPValidationError"
}
GET /api/v1/applications¶
List Applications
Description
List all applications owned by the authenticated user.
Returns a list of applications with minimal information (id, name, page_slug). Applications are sorted by creation date descending (newest first).
Input parameters
| Parameter | In | Type | Default | Nullable | Description |
|---|---|---|---|---|---|
HTTPBearer |
header | string | N/A | No | JWT Bearer token |
refreshed-token |
header | No | |||
token |
cookie | string | No |
Responses
[
{
"id": "string",
"name": "string",
"page_slug": null
}
]
Schema of the response body
{
"type": "array",
"items": {
"$ref": "#/components/schemas/ApplicationListItem"
},
"title": "Response List Applications Api V1 Applications Get"
}
{
"detail": [
{
"loc": [
null
],
"msg": "string",
"type": "string"
}
]
}
Schema of the response body
{
"properties": {
"detail": {
"items": {
"$ref": "#/components/schemas/ValidationError"
},
"type": "array",
"title": "Detail"
}
},
"type": "object",
"title": "HTTPValidationError"
}
PUT /api/v1/applications/{application_id}/page¶
Ensure Application Page
Description
Idempotently ensure this Application has a Page at slug.
Unlike POST /pages (create-only), this is safe to call repeatedly: the same slug
is a no-op, a different slug is rejected (we never silently rename a live URL), and a
slug owned by another application is rejected. Conflicts return 409 here (this
endpoint is new, so there is no client to break), while validation errors return 400.
Input parameters
| Parameter | In | Type | Default | Nullable | Description |
|---|---|---|---|---|---|
HTTPBearer |
header | string | N/A | No | JWT Bearer token |
application_id |
path | string | No | ||
refreshed-token |
header | No | |||
token |
cookie | string | No |
Request body
{
"slug": "string"
}
Schema of the request body
{
"properties": {
"slug": {
"type": "string",
"title": "Slug"
}
},
"type": "object",
"required": [
"slug"
],
"title": "Body_ensure_application_page_api_v1_applications__application_id__page_put"
}
Responses
{
"slug": "string",
"published": true,
"application": {
"id": "string",
"name": "string",
"is_private": true
},
"url": "string"
}
Schema of the response body
{
"properties": {
"slug": {
"type": "string",
"title": "Slug"
},
"published": {
"type": "boolean",
"title": "Published"
},
"application": {
"$ref": "#/components/schemas/PageApplicationInfo"
},
"url": {
"type": "string",
"title": "Url",
"description": "The public URL where this page is served.",
"readOnly": true
}
},
"type": "object",
"required": [
"slug",
"published",
"application",
"url"
],
"title": "PageResponse",
"description": "Response body for Page details."
}
{
"detail": [
{
"loc": [
null
],
"msg": "string",
"type": "string"
}
]
}
Schema of the response body
{
"properties": {
"detail": {
"items": {
"$ref": "#/components/schemas/ValidationError"
},
"type": "array",
"title": "Detail"
}
},
"type": "object",
"title": "HTTPValidationError"
}
Schemas¶
ApplicationCreate¶
| Name | Type | Description |
|---|---|---|
description |
||
generate_secret |
boolean | |
name |
string | |
page |
||
redirect_uris |
ApplicationCreateResponse¶
| Name | Type | Description |
|---|---|---|
brand_color |
||
client_secret |
||
description |
||
id |
string | |
image |
||
is_clientside_app |
boolean | Check if this is a client-side app based on privacy policy URL. Apps that went live through the Pages one-click path have privacy_statement set to the standard client-side privacy policy URL: that is their attestation. |
is_private |
boolean | An application is private if it is missing any of: description, URL, image, or privacy statement. |
name |
string | |
page |
||
privacy_statement |
||
published |
boolean | The App Directory is retired. Reflects the last stored listing; removed on 2026-10-12. |
redirect_uris |
||
url |
||
webhook_endpoints |
||
webhook_secret |
ApplicationListItem¶
| Name | Type | Description |
|---|---|---|
id |
string | |
name |
string | |
page_slug |
Body_ensure_application_page_api_v1_applications__application_id__page_put¶
| Name | Type | Description |
|---|---|---|
slug |
string |
HTTPValidationError¶
| Name | Type | Description |
|---|---|---|
detail |
Array<ValidationError> |
PageApplicationInfo¶
| Name | Type | Description |
|---|---|---|
id |
string | |
is_private |
boolean | |
name |
string |
PageResponse¶
| Name | Type | Description |
|---|---|---|
application |
PageApplicationInfo | |
published |
boolean | |
slug |
string | |
url |
string | The public URL where this page is served. |
ValidationError¶
| Name | Type | Description |
|---|---|---|
loc |
Array<> | |
msg |
string | |
type |
string |
Security schemes¶
| Name | Type | Scheme | Description |
|---|---|---|---|
| HTTPBearer | http | bearer | |
| HTTPBasic | http | basic |