stackapRequest access

Developers

API reference

The Stackap HTTP API exposes every operation the command-line tool and the dashboard perform, authenticated by a bearer token that belongs to exactly one organization.

Conventions

Every route is under /v1, sends and receives JSON, and takes Authorization: Bearer <token>. A token belongs to one organization, and the organization comes from the token alone. A resource in another organization returns the same 404 as one that does not exist. Errors are JSON with an error field, and some also carry a stable code. Roles are owner, member and platform admin; routes marked as operator-only return 403 to anyone else.

Projects

RouteWhat it does
POST /v1/projectsBody {slug, name}. Creates a project and its git repository. Returns the project. Refused with 403 at the organization's project limit (default 10).
GET /v1/projects, GET /v1/projects/:slugList projects, or read one.
PUT /v1/projects/:slug/settingsBody {port?, health_path?}; null resets a value. Applies from the next deploy. Owner only.

Deployments

RouteWhat it does
GET /v1/projects/:slug/deploymentsUp to 100 rows with id, number, status, build_id, image_ref, created_at, activated_at, retired_at and rolled_back_from.
GET /v1/projects/:slug/builds, GET /v1/builds/:id, GET /v1/builds/:id/logsBuilds, one build, and the log of any build by id.
POST /v1/projects/:slug/rollbackReturns {status, deployment}. 502 if the previous deployment is unhealthy, 409 if there is nothing to roll back to.
PUT /v1/projects/:slug/scaleBody {replicas}, 1 to 8. Platform admin only.

Variables and domains

RouteWhat it does
GET /v1/projects/:slug/envKeys and a mask, never values. System variables are flagged.
PUT /v1/projects/:slug/env/:keyBody {value}. 204. Refuses a system key with 409. DELETE removes one.
POST /v1/projects/:slug/domainsBody {hostname}. 201 with dns_status, ssl_status and an instructions object giving the A record to create.
GET /v1/projects/:slug/domains, DELETE …/domains/:hostnameList with refreshed status; detach.

Cron

RouteWhat it does
GET /v1/projects/:slug/cronJobs with their last status and last run time.
PUT /v1/projects/:slug/cron/:nameBody {schedule, path, enabled?}. UTC, five fields; the path starts with a slash.
POST /v1/projects/:slug/cron/importBody {crons: [{path, schedule}]} in vercel.json format. Returns {imported}.
GET /v1/projects/:slug/cron/:name/runsRun history.

Data, backups and metrics

RouteWhat it does
GET, POST /v1/projects/:slug/databaseRead or provision the project's database. Credentials are never returned.
GET /v1/projects/:slug/data/tables and …/tables/:schema/:tableTable browser reads with limit, offset, sort, dir and q. POST …/rows with {values} and DELETE …/rows with {key} write; owner only.
POST, GET /v1/projects/:slug/backupsTake a backup (201, {id, status}) or list the most recent 100.
POST /v1/projects/:slug/restoreBody {backup_id?}. Restores into a new database and returns its name. The live database is never modified.
POST /v1/backups/:id/verifyRestore a backup into a scratch database and compare row counts.
GET /v1/projects/:slug/metrics?range=1h|24h|7d, …/timelineLoad-time metrics and a timeline of what changed.
GET /v1/projects/:slug/logs?source=build|runtime&limit=NLogs, 1 to 5000 lines.

Access and organizations

RouteWhat it does
POST, GET /v1/api-tokens, DELETE /v1/api-tokens/:idBody {name, role?, scopes?, expires_in_days?}. Roles are owner and member. GET /v1/capabilities lists the scope names.
POST, GET /v1/ssh-keys, DELETE /v1/ssh-keys/:idRegister the public key you push with. Body {name, public_key}.
GET /v1/me, /v1/overview, /v1/activityWho you are, a dashboard summary, and recent changes in your organization. Values are never included.
POST, GET /v1/orgsPlatform admin only. Body {slug, name, max_projects?}; the reply includes an owner token shown once. POST …/orgs/:slug/disable and …/enable suspend and restore one.
GET /v1/approvals, GET /v1/approvals/:idYour organization's approval requests and their status (pending, approved, denied, consumed or expired). After an approval_required answer, poll the one you were given, then repeat the identical request once it is approved. The decision link is never in an API response.
DELETE /v1/projects/:slug, POST …/undeleteSoft-delete a project (it stops serving; code, database and backups are kept) and bring it back. With an approval-mode token the delete waits for a human approval.
GET /v1/status, /v1/alerts, /v1/platform/overviewPlatform admin only. Host-wide health, current alerts and the operator overview.

What this page is not

The list of routes and scopes is also generated by the server itself at /v1/capabilities and /v1/openapi.json, with no token needed. This page adds the request bodies and responses, written by reading the route files, so fields not mentioned here may exist. Where a body shape is not given, the route takes no body.

Early-access scope

Stackap is in early access. Tell us what you run and we will reply with a straight answer about whether it fits.

Ask for an invitation

Last updated .