Skip to main content

Slate functions

Generated from apiome-rest/openapi.yaml (API version 1.204.1) — do not edit by hand. How to authenticate is on the REST API reference.

Tag: slate-functions · 27 operations

GET /v1/slate/environments/{environment_id}/functions​

Get Function Policy

Return a lane's function policy, every function with its privileges, and what it runs.

Operation id: get_function_policy_v1_slate_environments__environment_id__functions_get

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get function policy.application/json FunctionPolicyResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/environments/{environment_id}/functions​

Create Function

Create a function, refusing an unsafe one by name.

Operation id: create_function_v1_slate_environments__environment_id__functions_post

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for create function.

Responses

StatusDescriptionBody
201Successful response for create function.application/json WriteFunctionResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/environments/{environment_id}/functions/approvals​

Record Function Approval

Record the approving half of dual control.

The approver is always the authenticated caller — there is no field by which one person can record somebody else's approval, which is the only version of two-person review that means anything. Approving one's own change is refused here as approval-self and again by V189's CHECK (approver_actor_key <> author_actor_key).

Operation id: record_function_approval_v1_slate_environments__environment_id__functions_approvals_post

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for record function approval.

Responses

StatusDescriptionBody
201Successful response for record function approval.application/json SlateFunctionsApprovalBody
422Validation Errorapplication/json HTTPValidationError

GET /v1/slate/environments/{environment_id}/functions/audit​

Get Function Audit

Return a lane's append-only function audit trail, most recent first.

Operation id: get_function_audit_v1_slate_environments__environment_id__functions_audit_get

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
limitqueryintegernoMaximum number of rows to return.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get function audit.application/json SlateFunctionsAuditResponse
422Validation Errorapplication/json HTTPValidationError

GET /v1/slate/environments/{environment_id}/functions/audit/export​

Export Function Audit

Export a lane's function audit trail as CSV.

VIEW rather than PUBLISH: §29.7 gives the Auditor read-only policy and exportable audit, and an export gated behind the permission to change functions would be an export the auditor cannot run.

Modelled on access_routes.py's exporter, and fixing the two defects that precedent carries.

CSV injection is neutralized. A cell whose first character is =, +, -, @, a tab or a carriage return is prefixed with an apostrophe. An actor display name and a refusal detail are attacker-influenced text, and the existing exporter writes them raw, so opening the evidence in a spreadsheet is a code-execution path.

Nothing is silently truncated. The existing exporter caps at 1000 rows with no signal, which in compliance evidence is a correctness bug rather than a performance choice: an auditor reading a truncated ledger concludes the missing entries never happened. This one reads one row past the cap, and when there are more it emits a final row saying so in words.

Reading the evidence is itself audit-worthy — who exported the record of who let a function read secrets is part of that record — so an export audit row is written before the download begins.

Operation id: export_function_audit_v1_slate_environments__environment_id__functions_audit_export_get

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
limitqueryintegernoMaximum number of rows to return.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for export function audit.application/json any
422Validation Errorapplication/json HTTPValidationError

GET /v1/slate/environments/{environment_id}/functions/invocations​

Get Function Invocations

Return a lane's invocation records, most recent first.

The filter names are the designer's dimension ids unchanged, so filtering on screen and filtering in a query cannot mean different things. variantRef is how "which function served this customer" gets narrowed down.

Operation id: get_function_invocations_v1_slate_environments__environment_id__functions_invocations_get

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
limitqueryintegernoMaximum number of rows to return.
functionRefquerystring or nullnoQuery parameter: function ref.
outcomequerystring or nullnoQuery parameter: outcome.
routequerystring or nullnoQuery parameter: route.
releaseIdquerystring or nullnoQuery parameter: release id.
regionquerystring or nullnoQuery parameter: region.
variantRefquerystring or nullnoQuery parameter: variant ref.
sourcequerystring or nullnoSource material descriptor (file, URL, paste, or discovery).
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get function invocations.application/json InvocationsResponse
422Validation Errorapplication/json HTTPValidationError

GET /v1/slate/environments/{environment_id}/functions/invocations/{invocation_id}​

Get Function Invocation

Return one invocation record with its redacted evidence.

Operation id: get_function_invocation_v1_slate_environments__environment_id__functions_invocations__invocation_id__get

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
invocation_idpathstringyesPath parameter identifying the invocation id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get function invocation.application/json InvocationBody
422Validation Errorapplication/json HTTPValidationError

PUT /v1/slate/environments/{environment_id}/functions/policy​

Set Function Policy

Change a lane's function policy: whether functions run, where, and within what ceilings.

Loosening residency to unrestricted with no stated reason is refused here with a sentence, and again by V189's CHECK. Both are deliberate: the operator should meet the explanation, not a constraint violation, and no future code path should be able to skip the explanation.

Operation id: set_function_policy_v1_slate_environments__environment_id__functions_policy_put

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for set function policy.

Responses

StatusDescriptionBody
200Successful response for set function policy.application/json SetFunctionPolicyResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/environments/{environment_id}/functions/simulate​

Simulate Function Invocation

Explain what this lane's policy decides for a test request, and why every function lost.

A read, not a write, unless persist is set — and VIEW rather than PUBLISH deliberately. "Which function served this customer", or "why did my function not run", is the question that brings an operator here during an incident, so requiring PUBLISH would put the answer out of reach of exactly the person asking.

Operation id: simulate_function_invocation_v1_slate_environments__environment_id__functions_simulate_post

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for simulate function invocation.

Responses

StatusDescriptionBody
200Successful response for simulate function invocation.application/json SlateFunctionsSimulateResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/environments/{environment_id}/functions/variants​

Create Variant

Create a personalization variant, refusing an unsafe one by name.

Operation id: create_variant_v1_slate_environments__environment_id__functions_variants_post

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for create variant.

Responses

StatusDescriptionBody
201Successful response for create variant.application/json WriteVariantResponse
422Validation Errorapplication/json HTTPValidationError

PUT /v1/slate/environments/{environment_id}/functions/variants/{variant_id}​

Replace Variant

Replace a personalization variant, running the same gates as a create.

Operation id: replace_variant_v1_slate_environments__environment_id__functions_variants__variant_id__put

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
variant_idpathstringyesPath parameter identifying the variant id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for replace variant.

Responses

StatusDescriptionBody
200Successful response for replace variant.application/json WriteVariantResponse
422Validation Errorapplication/json HTTPValidationError

DELETE /v1/slate/environments/{environment_id}/functions/variants/{variant_id}​

Remove Variant

Remove a personalization variant.

Operation id: remove_variant_v1_slate_environments__environment_id__functions_variants__variant_id__delete

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
variant_idpathstringyesPath parameter identifying the variant id segment.
expectedPolicyVersionqueryintegeryesRequired. Query parameter: expected policy version.
dryRunquerybooleannoWhen true, validate without persisting side effects.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for remove variant.application/json DeleteVariantResponse
422Validation Errorapplication/json HTTPValidationError

PUT /v1/slate/environments/{environment_id}/functions/{function_id}​

Replace Function

Replace a function, running the same gates as a create.

Operation id: replace_function_v1_slate_environments__environment_id__functions__function_id__put

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
function_idpathstringyesPath parameter identifying the function id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for replace function.

Responses

StatusDescriptionBody
200Successful response for replace function.application/json WriteFunctionResponse
422Validation Errorapplication/json HTTPValidationError

DELETE /v1/slate/environments/{environment_id}/functions/{function_id}​

Remove Function

Remove a function, keeping its body so the removal can be undone.

Operation id: remove_function_v1_slate_environments__environment_id__functions__function_id__delete

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
function_idpathstringyesPath parameter identifying the function id segment.
expectedPolicyVersionqueryintegeryesRequired. Query parameter: expected policy version.
dryRunquerybooleannoWhen true, validate without persisting side effects.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for remove function.application/json DeleteFunctionResponse
422Validation Errorapplication/json HTTPValidationError

PUT /v1/slate/environments/{environment_id}/functions/{function_id}/capabilities​

Grant Function Capability

Grant one runtime capability to a function.

Writing the row is the grant; there is no granted boolean to set. A grant with no stated reason is refused as capability-without-reason, and a grant of a standing privilege with no end date — or one so distant it is permanent in practice — as capability-unbounded.

Operation id: grant_function_capability_v1_slate_environments__environment_id__functions__function_id__capabilities_put

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
function_idpathstringyesPath parameter identifying the function id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for grant function capability.

Responses

StatusDescriptionBody
200Successful response for grant function capability.application/json CapabilityGrantResponse
422Validation Errorapplication/json HTTPValidationError

DELETE /v1/slate/environments/{environment_id}/functions/{function_id}/capabilities/{capability}​

Revoke Function Capability

Revoke one capability by deleting its grant row.

Deleting rather than flipping a flag is the whole design: the absence of a row is the denial, so a revocation cannot half-succeed into a state that still permits something.

Operation id: revoke_function_capability_v1_slate_environments__environment_id__functions__function_id__capabilities__capability__delete

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
function_idpathstringyesPath parameter identifying the function id segment.
capabilitypathstringyesPath parameter identifying the capability segment.
expectedPolicyVersionqueryintegeryesRequired. Query parameter: expected policy version.
dryRunquerybooleannoWhen true, validate without persisting side effects.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for revoke function capability.application/json DeleteGrantResponse
422Validation Errorapplication/json HTTPValidationError

PUT /v1/slate/environments/{environment_id}/functions/{function_id}/egress​

Set Function Egress Rule

Allowlist one outbound destination for a function.

Deny-by-default in the same shape as a capability: the row is the allowance, and there is no wildcard kind to write. An entry with no stated reason is refused, and an entry that does not actually cover the destinations the caller says it is for is refused as egress-unapproved rather than written and discovered to be inert in production.

Operation id: set_function_egress_rule_v1_slate_environments__environment_id__functions__function_id__egress_put

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
function_idpathstringyesPath parameter identifying the function id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for set function egress rule.

Responses

StatusDescriptionBody
200Successful response for set function egress rule.application/json EgressRuleResponse
422Validation Errorapplication/json HTTPValidationError

DELETE /v1/slate/environments/{environment_id}/functions/{function_id}/egress/{rule_id}​

Remove Function Egress Rule

Withdraw an egress allowance by deleting its row.

Operation id: remove_function_egress_rule_v1_slate_environments__environment_id__functions__function_id__egress__rule_id__delete

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
function_idpathstringyesPath parameter identifying the function id segment.
rule_idpathstringyesPath parameter identifying the rule id segment.
expectedPolicyVersionqueryintegeryesRequired. Query parameter: expected policy version.
dryRunquerybooleannoWhen true, validate without persisting side effects.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for remove function egress rule.application/json DeleteGrantResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/environments/{environment_id}/functions/{function_id}/revert​

Revert Function Route

Restore a function to a stored revision.

Reverting applies the recorded document rather than reconstructing intent from an audit sentence, which is what makes §29.5's "every function change can be reverted" a fact about this system rather than a claim about it.

Operation id: revert_function_route_v1_slate_environments__environment_id__functions__function_id__revert_post

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
function_idpathstringyesPath parameter identifying the function id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for revert function route.

Responses

StatusDescriptionBody
200Successful response for revert function route.application/json WriteFunctionResponse
422Validation Errorapplication/json HTTPValidationError

GET /v1/slate/environments/{environment_id}/functions/{function_id}/revisions​

Get Function Revisions

Return a function's revision history and its immutable versions, newest first.

Operation id: get_function_revisions_v1_slate_environments__environment_id__functions__function_id__revisions_get

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
function_idpathstringyesPath parameter identifying the function id segment.
limitqueryintegernoMaximum number of rows to return.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get function revisions.application/json SlateFunctionsRevisionsResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/environments/{environment_id}/functions/{function_id}/rollout​

Set Function Rollout

Advance or retreat a function's staged rollout.

This is where dual control actually bites. A function can be written in simulate freely; the write that puts code into the request path runs the same :func:app.slate_functions.evaluate_function_safety gate as a body edit, so it is refused as enforce-without-version, enforce-without-simulation, enforce-without-approval, approval-stale or approval-self rather than succeeding because it happened to arrive by a different route.

Operation id: set_function_rollout_v1_slate_environments__environment_id__functions__function_id__rollout_post

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
function_idpathstringyesPath parameter identifying the function id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for set function rollout.

Responses

StatusDescriptionBody
200Successful response for set function rollout.application/json WriteFunctionResponse
422Validation Errorapplication/json HTTPValidationError

PUT /v1/slate/environments/{environment_id}/functions/{function_id}/secrets​

Set Function Secret Ref

Declare a secret reference on a function.

There is no value field on this request and no value column in the schema behind it, which is §29.5's first flat prohibition made a schema impossibility rather than a validation. The half a schema cannot express — that the reference stays inside this function's own boundary — is refused here as secret-cross-project, with no acknowledgement path, because a cross-project reference is not a cost somebody may accept on their own authority.

Operation id: set_function_secret_ref_v1_slate_environments__environment_id__functions__function_id__secrets_put

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
function_idpathstringyesPath parameter identifying the function id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for set function secret ref.

Responses

StatusDescriptionBody
200Successful response for set function secret ref.application/json SecretRefResponse
422Validation Errorapplication/json HTTPValidationError

DELETE /v1/slate/environments/{environment_id}/functions/{function_id}/secrets/{ref_id}​

Remove Function Secret Ref

Withdraw a secret reference.

Operation id: remove_function_secret_ref_v1_slate_environments__environment_id__functions__function_id__secrets__ref_id__delete

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
function_idpathstringyesPath parameter identifying the function id segment.
ref_idpathstringyesPath parameter identifying the ref id segment.
expectedPolicyVersionqueryintegeryesRequired. Query parameter: expected policy version.
dryRunquerybooleannoWhen true, validate without persisting side effects.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for remove function secret ref.application/json DeleteGrantResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/environments/{environment_id}/functions/{function_id}/versions​

Add Function Version

Record a new immutable source version, optionally promoting it to live.

Versions are written once and never edited: promoting different code moves the function's activeVersionId rather than reshaping a stored artifact. Promoting is still a change to the function, so the function's prior body is recorded as a version-added revision before the pointer moves.

Operation id: add_function_version_v1_slate_environments__environment_id__functions__function_id__versions_post

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
function_idpathstringyesPath parameter identifying the function id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for add function version.

Responses

StatusDescriptionBody
201Successful response for add function version.application/json AddVersionResponse
422Validation Errorapplication/json HTTPValidationError

GET /v1/slate/functions/capabilities​

Get Function Capabilities

Return the runtime capability catalog, with what each grant opens and what it is unsafe for.

Deny-by-default is modelled as the absence of a row, so no table anywhere lists what the capabilities are. This endpoint is that list — versioned in code and reviewable in a diff rather than seeded per tenant — and it is the only way an operator can read what a grant costs before making one.

Operation id: get_function_capabilities_v1_slate_functions_capabilities_get

Parameters

NameInTypeRequiredDescription
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get function capabilities.application/json CapabilitiesResponse
422Validation Errorapplication/json HTTPValidationError

GET /v1/slate/functions/presets​

Get Function Presets

Return the residency postures and cache-key effects as data.

§29.7 gives the Publisher safe presets and never a runtime, and a preset is its fields rather than its name. A residency option that cannot say what it does not cover is one nobody can honestly choose, which is why doesNotCover is a required field here rather than documentation somewhere else.

Operation id: get_function_presets_v1_slate_functions_presets_get

Parameters

NameInTypeRequiredDescription
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get function presets.application/json FunctionPresetsResponse
422Validation Errorapplication/json HTTPValidationError

GET /v1/slate/functions/runtimes​

Get Function Runtimes

Return the execution runtime catalog.

Each runtime states what its sandbox contains and what escaping it would cost. A runtime that cannot say that is a runtime nobody can safely choose.

Operation id: get_function_runtimes_v1_slate_functions_runtimes_get

Parameters

NameInTypeRequiredDescription
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get function runtimes.application/json RuntimesResponse
422Validation Errorapplication/json HTTPValidationError

Schemas used​

AddVersionRequest​

Record a new immutable source version, optionally promoting it.

PropertyTypeRequiredDescription
sourceDigeststringyesContent address of the source.
bodyobjectnoThe version manifest.
runtimestringnoRuntime this version was built for.
sourceBytesinteger or nullnoSize in bytes, or null.
sourceOriginstringnoupload, build or import.
sourceRefstring or nullnoCommit, build id or upload ref.
activatebooleannoWhether to make this the live version.
expectedPolicyVersionintegeryesThe version the caller read.
dryRunbooleannoValidate without writing.
reasonstringnoWhy; recorded in audit.

AddVersionResponse​

The outcome of adding a version.

PropertyTypeRequiredDescription
appliedbooleanyesFalse for a dry run.
dryRunbooleanyesWhether this was a preview.
versionFunctionVersionBody or nullnoThe version written.
activatedbooleanyesWhether it was promoted to live.
policyVersionintegeryesThe version after the write.
enforcementSlateFunctionsEnforcementBodynoEnforcement.

CapabilitiesResponse​

The runtime capability catalog.

Deny-by-default is the absence of a grant row, so there is no table anywhere listing what the capabilities are. This is that list, versioned in code rather than seeded per tenant, which is the only way an operator can read what a grant opens before making one.

PropertyTypeRequiredDescription
capabilitiesarray of CapabilityBodyyesEvery capability, safest first.

CapabilityGrantResponse​

The outcome of a capability grant.

PropertyTypeRequiredDescription
appliedbooleanyesFalse for a dry run.
dryRunbooleanyesWhether this was a preview.
capabilityCapabilityGrantBody or nullnoThe grant.
policyVersionintegeryesThe version after the write.
enforcementSlateFunctionsEnforcementBodynoEnforcement.
warningsarray of FunctionWarningBodynoWarnings.

DeleteFunctionResponse​

The outcome of a function deletion.

PropertyTypeRequiredDescription
deletedbooleanyesFalse for a dry run.
dryRunbooleanyesWhether this was a preview.
policyVersionintegeryesThe version after the write.

DeleteGrantResponse​

The outcome of revoking a grant, an allowance or a reference.

Revoking is a DELETE, because the absence of a row is the denial. There is no field here reporting a granted flag, because there is no such column to report.

PropertyTypeRequiredDescription
deletedbooleanyesFalse for a dry run.
dryRunbooleanyesWhether this was a preview.
policyVersionintegeryesThe version after the write.

DeleteVariantResponse​

The outcome of removing a variant.

PropertyTypeRequiredDescription
deletedbooleanyesFalse for a dry run.
dryRunbooleanyesWhether this was a preview.
policyVersionintegeryesThe version after the write.

EgressRuleResponse​

The outcome of an egress allowlist write.

PropertyTypeRequiredDescription
appliedbooleanyesFalse for a dry run.
dryRunbooleanyesWhether this was a preview.
egressEgressRuleBody or nullnoThe entry as written.
policyVersionintegeryesThe version after the write.
warningsarray of FunctionWarningBodynoWarnings.

FunctionPolicyResponse​

A lane's complete function policy, and what it actually runs.

PropertyTypeRequiredDescription
environmentIdstringyesThe lane.
functionsEnabledbooleanyesWhether functions may exist on this lane at all.
policyVersionintegeryesOptimistic-concurrency token.
edgeAttachedbooleanyesWhether a runtime tier serves this lane.
edgeProviderstring or nullnoIts name, or null.
defaultRegionstringyesWhere functions run by default.
defaultResidencyClassstringyesThe lane's residency posture.
defaultCpuMsLimitintegeryesCPU ceiling a function may tighten.
defaultMemoryMbLimitintegeryesMemory ceiling a function may tighten.
defaultWallMsLimitintegeryesWall-clock ceiling a function may tighten.
residencyWaiverReasonstring or nullnoWhy residency was loosened, when it was.
enforcementSlateFunctionsEnforcementBodynoWhether the policy runs anything.
functionsarray of FunctionBodyyesFunctions, in precedence order.
functionsDigeststringyesDeterminism receipt over the enabled function set.
updatedAtstring or nullnoWhen the policy last changed.
updatedBystring or nullnoWho changed it.

FunctionPresetsResponse​

The safe presets a Publisher may choose between without ever touching a runtime.

PropertyTypeRequiredDescription
residencyClassesarray of SlateFunctionsResidencyClassBodyyesThe three residency postures.
cacheKeyEffectsarray of CacheKeyEffectBodyyesThe three cache-key effects.

GrantCapabilityRequest​

Grant one runtime capability to a function.

PropertyTypeRequiredDescription
capabilitystringyesWhich capability, from the catalog.
reasonstringyesWhy the function needs it.
expiresAtstring or nullnoWhen the grant lapses. Required for the standing privileges.
expectedPolicyVersionintegeryesThe version the caller read.
dryRunbooleannoValidate without writing.

HTTPValidationError​

Validation error response emitted when request data fails schema checks.

PropertyTypeRequiredDescription
detailarray of ValidationErrornoDetail.

InvocationBody​

One invocation record, with its redacted evidence.

PropertyTypeRequiredDescription
idstringyesInvocation id.
atstring or nullnoWhen it was recorded.
sourcestringnopolicy-simulation or edge-observed.
functionRefstringnoThe function that decided.
functionLabelstringnoIts label as it read at the time.
routestringnoThe request path.
methodstringnoThe request method.
releaseIdstring or nullnoRelease active at the time.
regionstring or nullnoRegion, when known.
variantRefstring or nullnoVariant selected, when one was.
outcomestringnoWhat the evaluation concluded.
executedbooleannoWhether code actually ran.
edgeAttachedbooleannoWhether a runtime tier was attached.
cpuMsinteger or nullnoCPU consumed, or null.
wallMsinteger or nullnoWall-clock elapsed, or null.
memoryPeakMbinteger or nullnoPeak memory, or null.
denialReasonstring or nullnoWhy a denial happened.
evidencemap of stringnoRedacted request evidence.
retainUntilstring or nullnoWhen the evidence is purged.

InvocationsResponse​

A lane's invocation records.

PropertyTypeRequiredDescription
invocationsarray of InvocationBodyyesMost recent first.
observedbooleannoFalse: none of these were observed in a request path.
sentencestringnoWhat that means.
runtimeSentencestringnoWhy there are no resource measurements.

RuntimesResponse​

The execution runtime catalog.

PropertyTypeRequiredDescription
runtimesarray of RuntimeBodyyesEvery runtime, narrowest sandbox first.

SecretRefResponse​

The outcome of declaring a secret reference.

PropertyTypeRequiredDescription
appliedbooleanyesFalse for a dry run.
dryRunbooleanyesWhether this was a preview.
secretSecretRefBody or nullnoThe reference as written.
policyVersionintegeryesThe version after the write.

SetEgressRuleRequest​

Allowlist one outbound destination for a function.

PropertyTypeRequiredDescription
destinationKindstringnoexact-host or host-suffix.
destinationstringyesThe host or host suffix.
schemestringnohttps or http.
portinteger or nullnoPermitted port, or null for default.
methodsarray of stringnoMethods; empty means every one.
reasonstringyesWhy this destination is reachable.
expiresAtstring or nullnoWhen it lapses, or null.
destinationsarray of stringnoDestinations this entry is meant to cover, checked here.
expectedPolicyVersionintegeryesThe version the caller read.
dryRunbooleannoValidate without writing.

SetFunctionPolicyRequest​

Change a lane's function policy: whether functions run, where, and within what ceilings.

PropertyTypeRequiredDescription
functionsEnabledbooleannoWhether functions may exist here.
defaultRegionstringnoWhere functions run by default.
defaultResidencyClassstringnoin-region-only, region-pinned or unrestricted.
defaultCpuMsLimitintegernoCPU ceiling in milliseconds.
defaultMemoryMbLimitintegernoMemory ceiling in MB.
defaultWallMsLimitintegernoWall-clock ceiling in ms.
residencyWaiverReasonstring or nullnoRequired when residency is unrestricted.
expectedPolicyVersionintegeryesThe version the caller read.
dryRunbooleannoRun every gate and write nothing.
reasonstringnoWhy; recorded in audit.

SetFunctionPolicyResponse​

The outcome of a function policy change.

PropertyTypeRequiredDescription
appliedbooleanyesFalse for a dry run.
dryRunbooleanyesWhether this was a preview.
functionsEnabledbooleanyesWhether functions may exist, after the change.
defaultResidencyClassstringyesThe residency posture now in effect.
policyVersionintegeryesThe version after the change.
enforcementSlateFunctionsEnforcementBodynoEnforcement.
warningsarray of FunctionWarningBodynoWarnings.

SetSecretRefRequest​

Declare a secret reference on a function. There is no value field, by construction.

PropertyTypeRequiredDescription
secretNamestringyesName of the secret in the vault that holds the material.
aliasstringyesIdentifier the function code binds to.
scopestringnofunction or environment.
ownerTenantIdstringnoTenant the secret belongs to. A differing value is refused.
ownerEnvironmentIdstringnoEnvironment the secret belongs to. A differing value is refused.
ownerFunctionIdstringnoFunction the secret belongs to, for a function-scoped reference.
expectedPolicyVersionintegeryesThe version the caller read.
dryRunbooleannoValidate without writing.

SlateFunctionsApprovalBody​

One recorded approval.

PropertyTypeRequiredDescription
idstringyesApproval id.
subjectKindstringnoWhat was approved.
subjectIdstringnoId of the subject.
digeststringnoThe body that was reviewed.
authorActorNamestringnoWho proposed it.
approverActorNamestringnoWho approved it.
approvedAtstring or nullnoWhen.
notestring or nullnoReviewer note, when there is one.

SlateFunctionsApprovalRequest​

Record a second person's approval of one exact body.

PropertyTypeRequiredDescription
subjectKindenum "policy", "function", "version", "capability", "egress-rule", "variant"yesWhat is being approved.
subjectIdstringyesId of the subject.
digeststringyesThe body that was reviewed, from the write response.
authorActorKeystringyesImmutable identity of whoever proposed it.
authorActorNamestringnoThe proposer's display name.
notestring or nullnoOptional reviewer note.

SlateFunctionsAuditResponse​

A lane's function audit trail.

PropertyTypeRequiredDescription
entriesarray of SlateFunctionsAuditEntryBodyyesMost recent first.

SlateFunctionsRevertRequest​

Restore a function to a stored revision.

PropertyTypeRequiredDescription
revisionintegeryesWhich stored revision to apply.
expectedPolicyVersionintegeryesThe version the caller read.
dryRunbooleannoValidate without writing.
reasonstringnoWhy; recorded in audit.

SlateFunctionsRevisionsResponse​

A function's revision history.

PropertyTypeRequiredDescription
revisionsarray of SlateFunctionsRevisionBodyyesNewest first.
versionsarray of FunctionVersionBodynoThe immutable versions alongside them.

SlateFunctionsRolloutRequest​

Advance or retreat a function's staged rollout.

PropertyTypeRequiredDescription
rolloutModestringyessimulate or enforce.
rolloutPercentintegeryesShare of traffic, 0 to 100.
expectedPolicyVersionintegeryesThe version the caller read.
dryRunbooleannoValidate without writing.
reasonstringnoWhy; recorded in audit.

SlateFunctionsSimulateCommandBody​

A simulation, optionally over a what-if function set.

PropertyTypeRequiredDescription
requestSlateFunctionsSimulateRequestBodyyesThe test request.
functionsarray of FunctionBody or nullnoWhat-if overlay. When absent, the lane's stored functions are used.
persistbooleannoRecord the outcome as an invocation.

SlateFunctionsSimulateResponse​

What the policy decides for a test request, and why every other function did not.

basis, observed, executed and enforced are literal defaults no handler assigns. There is no code path able to make this response claim that a request was observed or that code ran, which is the structural form of the same guarantee V189 expresses as CHECKs.

PropertyTypeRequiredDescription
outcomestringyesWhat the policy concluded. Never 'ran'.
outcomeReasonstringyesOne sentence naming the outcome and what produced it.
functionRefstring or nullnoThe function that won.
functionLabelstringyesIts name.
versionRefstring or nullnoThe version that would have run.
runtimestringyesThe runtime it declares.
rolloutModestringyesIts rollout mode.
rolloutPercentintegeryesIts rollout percentage.
regionstringyesWhere it would have run.
residencyClassstringyesThe residency posture it would have run under.
limitsmap of integernoThe ceilings it runs within.
variantRefstring or nullnoThe variant selected.
variantLabelstringyesIts name.
fallbackVariantstringyesWhat every unmatched reader receives.
cacheKeyEffectstringyesThe resolved effect on the shared cache key.
privacyClassstringyesThe privacy classification of the selected variant.
consentBasisstringyesIts consent basis.
analyticsDimensionstringyesThe dimension it reports under.
capabilitiesGrantedarray of stringnoHeld and used.
capabilitiesDeniedarray of stringnoAsked for and not held. Deny-by-default surfaces here.
egressAllowedarray of stringnoDestinations covered.
egressDeniedarray of stringnoDestinations not covered.
denialReasonstring or nullnoWhy a denial happened.
consideredarray of SlateFunctionsSimulationStepBodyyesEvery function and variant, and why it did not win.
warningsarray of FunctionWarningBodynoWarnings.
functionsDigeststringyesDeterminism receipt over the evaluated function set.
policyVersionintegeryesWhich policy generation answered.
basis"policy-simulation"noThis is an evaluation of recorded policy against a test request, not a replay of an observed request. When a runtime tier lands, 'edge-observed' becomes the second value of this field rather than a change of meaning for the first.
observedbooleannoFalse: no runtime tier reported this request.
executedfalsenoFalse: no code ran, because there is nothing to run it in.
enforcedfalsenoFalse: nothing acted on this request.
sentencestringnoWhat all of that means, in words.
runtimeSentencestringnoWhy there are no resource measurements.
invocationIdstring or nullnoSet when the outcome was recorded.

WriteFunctionRequest​

Create or replace a function.

PropertyTypeRequiredDescription
idstring or nullnoFunction id, absent before it is written.
ordinalintegernoPrecedence; lower wins.
enabledbooleannoWhether the function participates.
labelstringnoOperator-facing function name.
matcherKindstringnoexact, prefix, glob or regex.
matcherValuestringnoThe route pattern.
matcherMethodsarray of stringnoMethods; empty is all.
matcherHostsarray of stringnoHosts; empty is all.
runtimestringnojs-isolate or wasm.
activeVersionIdstring or nullnoThe live version, or null.
rolloutModestringnosimulate or enforce.
rolloutPercentintegernoShare of traffic, 0 to 100.
regionstring or nullnoRegion override, or null to inherit.
residencyClassstring or nullnoResidency override, or null to inherit.
cpuMsLimitinteger or nullnoCPU override, or null.
memoryMbLimitinteger or nullnoMemory override, or null.
wallMsLimitinteger or nullnoWall-clock override, or null.
envVarNamesarray of stringnoNon-secret environment variable names. Names only.
declaredDestinationsarray of stringnoHosts the version manifest says the code will call.
acknowledgedWarningsarray of stringnoWarning reasons the operator accepted.
bodyDigeststringnoContent digest of the decisive fields; what an approval names.
revisionintegernoMonotonic revision counter.
capabilitiesarray of CapabilityGrantBodynoLive capability grants. Absence of one is a denial.
egressarray of EgressRuleBodynoEgress allowlist entries. Absence of one is a denial.
secretsarray of SecretRefBodynoSecret references. References only, never values.
variantsarray of VariantBodynoPersonalization variants, in selection order.
expectedPolicyVersionintegeryesThe version the caller read.
dryRunbooleannoValidate without writing.
reasonstringnoWhy; recorded in audit.

WriteFunctionResponse​

The outcome of a function write.

PropertyTypeRequiredDescription
appliedbooleanyesFalse for a dry run.
dryRunbooleanyesWhether this was a preview.
functionFunctionBody or nullnoThe function as written.
bodyDigeststringyesWhat an approval of this body must name.
policyVersionintegeryesThe version after the write.
enforcementSlateFunctionsEnforcementBodynoEnforcement.
warningsarray of FunctionWarningBodynoWarnings.

WriteVariantRequest​

Create or replace a personalization variant.

PropertyTypeRequiredDescription
idstring or nullnoVariant id, absent before it is written.
functionIdstringnoFunction that selects between variants.
ordinalintegernoPrecedence among variants; lower wins.
enabledbooleannoWhether the variant participates.
labelstringnoOperator-facing name.
audienceKindstringnogeo, language, device, cohort or experiment.
audienceMatcherarray of objectnoThe audience predicates.
fallbackVariantstringnoWhat every reader the audience rule does not match receives.
cacheKeyEffectstringnonone, vary-on-dimension or bypass-cache.
varyDimensionstringnoWhat the cache key varies on.
analyticsDimensionstringnoThe dimension it reports under.
privacyClassstringnonon-personal, pseudonymous or personal.
consentBasisstringnonot-required, explicit-consent or legitimate-interest.
expectedPolicyVersionintegeryesThe version the caller read.
dryRunbooleannoValidate without writing.
reasonstringnoWhy; recorded in audit.

WriteVariantResponse​

The outcome of a variant write.

PropertyTypeRequiredDescription
appliedbooleanyesFalse for a dry run.
dryRunbooleanyesWhether this was a preview.
variantVariantBody or nullnoThe variant as written.
policyVersionintegeryesThe version after the write.
warningsarray of FunctionWarningBodynoWarnings.