Skip to main content

Slate

Generated from apiome-rest/openapi.yaml (API version 1.204.1) — do not edit by hand. How to authenticate is on the REST API reference.

Tag: slate · 17 operations

GET /v1/slate/domains/{domain_id}​

Get Domain Detail

Return one domain with its DNS instructions, checklist and certificate state.

Operation id: get_domain_detail_v1_slate_domains__domain_id__get

Parameters

NameInTypeRequiredDescription
domain_idpathstringyesPath parameter identifying the domain id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get domain detail.application/json DomainResponse
422Validation Errorapplication/json HTTPValidationError

DELETE /v1/slate/domains/{domain_id}​

Remove Domain

Detach a domain from its lane.

The row is deleted rather than tombstoned: it is what makes the global hostname claim and the issuance authorization true, and a retained row would keep a hostname claimed against whoever registers it next.

Operation id: remove_domain_v1_slate_domains__domain_id__delete

Parameters

NameInTypeRequiredDescription
domain_idpathstringyesPath parameter identifying the domain id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
204Successful response for remove domain.—
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/domains/{domain_id}/certificate​

Probe Domain Certificate

Complete a TLS handshake with the host and record what it is serving.

This is the whole of "Renew now" as an honest action. Renewal is the edge's job and it does it on a schedule; what an operator actually wants from that button is confirmation, so this measures the live host and reports the certificate it found — including, when the serial has changed, that a renewal has already happened.

A probe that fails is recorded and returned as a 200 with tlsStatus: "error" and the reason, for the same reason a failed DNS check is: an unreachable host is a state to display, not an exception to raise.

Operation id: probe_domain_certificate_v1_slate_domains__domain_id__certificate_post

Parameters

NameInTypeRequiredDescription
domain_idpathstringyesPath parameter identifying the domain id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for probe domain certificate.application/json DomainResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/domains/{domain_id}/primary​

Make Domain Primary

Make a domain the lane's canonical host; the others become redirects to it.

Refused for an unverified host: a canonical host that does not resolve here would redirect every alias to a name that fails, taking the working aliases down with it.

Operation id: make_domain_primary_v1_slate_domains__domain_id__primary_post

Parameters

NameInTypeRequiredDescription
domain_idpathstringyesPath parameter identifying the domain id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for make domain primary.application/json DomainResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/domains/{domain_id}/renewal​

Set Domain Renewal

Switch automatic certificate renewal on or off.

Switching it off withdraws the edge's authorization to obtain a certificate for the host at all, so it parks a domain immediately rather than in ninety days' time.

Operation id: set_domain_renewal_v1_slate_domains__domain_id__renewal_post

Parameters

NameInTypeRequiredDescription
domain_idpathstringyesPath parameter identifying the domain id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for set domain renewal.

Responses

StatusDescriptionBody
200Successful response for set domain renewal.application/json DomainResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/domains/{domain_id}/verify​

Verify Domain

Read the tenant's public DNS now and record whether ownership is proven.

A failed check is a 200 with verified: false, not an error: "the record is not there yet" is the normal state of a domain someone attached ninety seconds ago, and answering 4xx would make the screen show an error banner for the expected path. Only an inability to ask — a resolver that timed out, a truncated answer — is a 502, because that is a statement about this platform rather than about the tenant's DNS.

Operation id: verify_domain_v1_slate_domains__domain_id__verify_post

Parameters

NameInTypeRequiredDescription
domain_idpathstringyesPath parameter identifying the domain id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for verify domain.application/json VerifyResponse
422Validation Errorapplication/json HTTPValidationError

GET /v1/slate/environments/{environment_id}​

Get Environment State

Report what a lane is serving, how far it reached, and against what budget.

Operation id: get_environment_state_v1_slate_environments__environment_id__get

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get environment state.application/json EnvironmentResponse
422Validation Errorapplication/json HTTPValidationError

GET /v1/slate/environments/{environment_id}/domains​

List Environment Domains

List a lane's custom domains with their DNS instructions and certificate state.

Operation id: list_environment_domains_v1_slate_environments__environment_id__domains_get

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for list environment domains.application/json DomainListResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/environments/{environment_id}/domains​

Attach Environment Domain

Attach a hostname to a lane and answer with the DNS records that make it work.

The domain starts unverified and with no certificate: nothing has been proven, and because /tls/authorize refuses an unverified host, nothing is being provisioned either.

Operation id: attach_environment_domain_v1_slate_environments__environment_id__domains_post

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for attach environment domain.

Responses

StatusDescriptionBody
201Successful response for attach environment domain.application/json DomainResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/environments/{environment_id}/promote​

Promote Release

Route a lane to an already-built artifact. Never rebuilds.

A refused promotion still records an audit entry naming the reason, so an operator can later see what was attempted and why it was stopped.

Operation id: promote_release_v1_slate_environments__environment_id__promote_post

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for promote release.

Responses

StatusDescriptionBody
200Successful response for promote release.application/json ActivationResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/environments/{environment_id}/rollback​

Rollback Environment

Route a lane back to its most recent retained artifact.

Deliberately does not consult approval freshness: requiring fresh sign-off to stop serving a bad release would make the approval policy an outage amplifier.

Operation id: rollback_environment_v1_slate_environments__environment_id__rollback_post

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for rollback environment.

Responses

StatusDescriptionBody
200Successful response for rollback environment.application/json ActivationResponse
422Validation Errorapplication/json HTTPValidationError

GET /v1/slate/releases/{release_id}​

Get Release Detail

Load one release with its full evidence.

Operation id: get_release_detail_v1_slate_releases__release_id__get

Parameters

NameInTypeRequiredDescription
release_idpathstringyesPath parameter identifying the release id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get release detail.application/json ReleaseBody
422Validation Errorapplication/json HTTPValidationError

GET /v1/slate/sites​

List Managed Sites

List the tenant's managed sites with their environment lanes.

This is how the Release Center resolves a project to a site and its lanes; it works in terms of a project and a version, not a site id. An empty list is a legitimate answer meaning "this project is not hosted", which is different from an error.

Operation id: list_managed_sites_v1_slate_sites_get

Parameters

NameInTypeRequiredDescription
projectIdquerystring or nullnoRestrict to one project's sites.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for list managed sites.application/json SiteListResponse
422Validation Errorapplication/json HTTPValidationError

GET /v1/slate/sites/{site_id}/releases​

List Site Releases

List a site's release timeline, newest first.

Operation id: list_site_releases_v1_slate_sites__site_id__releases_get

Parameters

NameInTypeRequiredDescription
site_idpathstringyesPath parameter identifying the site id segment.
environmentIdquerystring or nullnoRestrict the timeline to one environment.
limitqueryintegernoMaximum releases to return.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for list site releases.application/json ReleaseListResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/sites/{site_id}/releases​

Create Site Release

Record a built release, refusing an artifact whose signature does not verify.

Verification happens at record time as well as at activation. Storing an unverifiable artifact and only discovering it during an incident promotion would put the discovery at the worst possible moment.

Operation id: create_site_release_v1_slate_sites__site_id__releases_post

Parameters

NameInTypeRequiredDescription
site_idpathstringyesPath parameter identifying the site id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for create site release.

Responses

StatusDescriptionBody
201Successful response for create site release.application/json ReleaseBody
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/sites/{site_id}/retention​

Run Retention

Reap artifacts that have fallen outside the site's rollback window.

Retention and rollback capability are the same setting, so the sweep is deliberately conservative: the active release is never reaped, and only releases that once served are candidates.

Operation id: run_retention_v1_slate_sites__site_id__retention_post

Parameters

NameInTypeRequiredDescription
site_idpathstringyesPath parameter identifying the site id segment.
environmentIdquerystringyesEnvironment whose history to sweep.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for run retention.application/json RetentionResponse
422Validation Errorapplication/json HTTPValidationError

GET /v1/slate/tls/authorize​

Authorize Tls

Answer the edge's on-demand TLS question: may this hostname be issued for?

Unauthenticated by necessity and by design. The caller is a TLS handshake, which has no session to present. It supplies a hostname it already has and learns only whether this platform will serve it — the same thing it would learn by connecting. Every other route on this surface requires VERSIONS/PUBLISH.

Answers 200 only for a domain that exists, is verified, and has renewal enabled; everything else is 403, which is what Caddy reads as "do not order a certificate". A permissive answer here would let anyone point a hostname at us and have certificates issued in our ACME account until the rate limit stopped them, so the check is a single conjunction with no fallbacks.

Operation id: authorize_tls_v1_slate_tls_authorize_get

Parameters

NameInTypeRequiredDescription
domainquerystringyesThe hostname the edge received over SNI.

Responses

StatusDescriptionBody
200Successful response for authorize tls.application/json AuthorizeResponse
422Validation Errorapplication/json HTTPValidationError

Schemas used​

ActivationRequest​

Promote or roll back a lane.

PropertyTypeRequiredDescription
releaseIdstring or nullnoRelease to promote. Ignored by rollback, which selects its own target.
dryRunbooleannoRun every gate and return the plan without changing routing.
requireApprovalbooleannoEnforce this lane's approval policy for the promotion.

ActivationResponse​

Outcome of a promotion or rollback.

PropertyTypeRequiredDescription
appliedbooleanyesApplied.
dryRunbooleanyesDry Run.
planobjectyesPlan.
activationIdstring or nullnoActivation ID.
routingVersioninteger or nullnoRouting Version.
activatedAtstring or nullnoActivated At.

AttachDomainRequest​

Attach a hostname to a lane.

PropertyTypeRequiredDescription
hoststringyesThe domain, with or without a scheme — it is normalized here.
isPrimarybooleannoMake this the lane's canonical host, demoting the current one.
verificationMethodstring or nullnoOverride the derived method (cname for a subdomain, txt for an apex). Provided because apex detection is a heuristic, not the Public Suffix List.

AuthorizeResponse​

The edge's on-demand TLS answer for one hostname.

PropertyTypeRequiredDescription
domainstringyesDomain.
allowedbooleanyesAllowed.
reasonstringyesFor the edge's log. Not shown to a browser.

CreateReleaseRequest​

Record a built release and its artifact.

PropertyTypeRequiredDescription
environmentIdstringyesLane the release targets.
releaseRefstringyesShort human-quotable id, unique per site.
sourceReleaseSourceBodyyesProvenance source for the record (for example human or imported).
contentDigeststringyesDigest of the rendered bytes.
sourceDigeststringyesDigest of the source inputs.
configDigeststringyesDigest of the build configuration.
signaturestringyesDetached signature over the three digests.
signatureKeyIdstringyesId of the signing key.
storageUristringyesWhere the artifact bytes live.
manifestobjectnoBuild manifest / SBOM.
pageCountintegernoRendered page count.
sizeBytesintegernoTotal artifact size in bytes.
statusenum "ready", "review"noInitial state of the built release.
impactobjectnoCache/security consequences of activation.

DomainListResponse​

A lane's domains and the edge policy that applies to all of them.

PropertyTypeRequiredDescription
environmentIdstringyesEnvironment ID.
domainsarray of DomainBodynoDomains.
tlsPolicyTlsPolicyBodyyesTls Policy.
dnsTargetstringyesThe platform hostname custom domains are pointed at.

DomainResponse​

One domain, plus the edge policy, so a single-domain screen needs one call.

PropertyTypeRequiredDescription
domainDomainBodyyesDomain.
tlsPolicyTlsPolicyBodyyesTls Policy.

EnvironmentResponse​

Lane state: what is serving, how far it reached, and against what budget.

PropertyTypeRequiredDescription
idstringyesStable resource identifier.
siteIdstringyesSite ID.
kindstringyesKind.
namestringyesHuman-readable name.
activeReleaseIdstring or nullyesActive Release ID.
routingVersionintegeryesRouting Version.
robotsExcludedbooleanyesRobots Excluded.
accessPolicystringyesAccess Policy.
expiresAtstring or nullnoExpires At.
rolloutobjectnoRollout.
activationSloobjectnoActivation Slo.
domainsarray of objectnoDomains.

HTTPValidationError​

Validation error response emitted when request data fails schema checks.

PropertyTypeRequiredDescription
detailarray of ValidationErrornoDetail.

ReleaseBody​

One immutable release, shaped to the Release Center's release record.

PropertyTypeRequiredDescription
idstringyesStable resource identifier.
releaseRefstringyesRelease Ref.
environmentstringyesEnvironment.
environmentIdstringyesEnvironment ID.
statusstringyesStatus.
sourceReleaseSourceBodyyesProvenance source for the record (for example human or imported).
artifactReleaseArtifactBodyyesArtifact.
actorReleaseActorBodyyesActor.
createdAtstringyesCreated At.
activatedAtstring or nullnoActivated At.
activationCompletedAtstring or nullnoActivation Completed At.
deactivatedAtstring or nullnoDeactivated At.
trafficobject or nullnoTraffic.
impactobjectnoImpact.
domainsarray of objectnoDomains.
checksarray of objectnoChecks.
phasesarray of objectnoPhases.
approvalsarray of objectnoApprovals.
changedPagesarray of objectnoChanged Pages.
logsarray of objectnoLogs.
auditarray of objectnoAudit.

ReleaseListResponse​

The release timeline.

PropertyTypeRequiredDescription
releasesarray of ReleaseBodyyesReleases.

RenewalRequest​

Switch automatic certificate renewal for a domain.

PropertyTypeRequiredDescription
autoRenewbooleanyesWhether the edge may obtain and renew certificates.

RetentionResponse​

Outcome of a retention sweep.

PropertyTypeRequiredDescription
reapedintegeryesReaped.
reapedReleaseIdsarray of stringyesReaped Release IDs.
retainedReleasesintegeryesRetained Releases.

SiteListResponse​

The tenant's managed sites.

PropertyTypeRequiredDescription
sitesarray of SiteBodyyesSites.

VerifyResponse​

The outcome of an ownership check.

PropertyTypeRequiredDescription
domainDomainBodyyesDomain.
verifiedbooleanyesVerified.
detailstringyesWhat was observed — the actionable part of a failure.
tlsPolicyTlsPolicyBodyyesTls Policy.