PROTOTYPE / DESIGN PARTNER PREVIEW
Prototype HTTP reference.
The actual routes in the downloadable fixture. These are not a stable managed API.
Authentication
Except for health, requests use Authorization: Bearer <token>. The local wrapper writes REPRO_ALPHA_TOKEN and REPRO_BETA_TOKEN to .env. Use them in your client without publishing that file.
Routes
| Method and path | Behavior |
|---|---|
GET /health | Returns health and release label. |
GET /records | Lists up to 100 records for the caller’s tenant. |
POST /records | Creates or conditionally updates a record. |
POST /tools | Creates or conditionally updates tool source. |
POST /run/:id | Runs the tenant’s enabled tool. |
DELETE /tools/:id | Revokes future executions; does not erase source. |
Record mutation
{
"id": "research-digest",
"title": "A useful research note",
"expectedVersion": 0
}expectedVersion: 0 creates a record. Updates require the current version. Successful mutations return the identifier and incremented version. IDs contain 1–64 lowercase letters, digits or hyphens; titles are at most 500 characters.
Tool mutation
{
"id": "research-digest",
"code": "export default { async fetch(req, env) { return Response.json(JSON.parse(env.INPUT)); } }",
"expectedVersion": 0
}The stored source must be a Worker module. The fixture limits it to 16,000 characters. Successful source updates re-enable the tool. The runner returns { version, result }; the module must return JSON.
Mutation limits and errors
Record and tool mutations require JSON and a Content-Length between 1 and 32,768 bytes. Invalid input returns 400; missing authorization 401; revoked execution 403; a missing tool 404; a stale version 409; oversized or missing-length mutation bodies 413.
Other runtime failures are not a stabilized public error contract. For exact behavior, read src/api.ts.