Repository navigation
Conversation
kong
Bot
force-pushed
the
chore/sync-openapi
branch
from
August 28, 2026 13:58
7cd039d to
b69cdc1
Compare
kong
Bot
force-pushed
the
chore/sync-openapi
branch
4 times, most recently
from
August 30, 2026 12:25
ebe76ec to
5660716
Compare
kong
Bot
force-pushed
the
chore/sync-openapi
branch
from
September 10, 2026 22:00
5660716 to
697020d
Compare
|
|
kong
Bot
force-pushed
the
chore/sync-openapi
branch
13 times, most recently
from
September 17, 2026 18:04
ebaec87 to
2891cbb
Compare
kong
Bot
force-pushed
the
chore/sync-openapi
branch
8 times, most recently
from
September 19, 2026 06:17
2768536 to
0d69f5d
Compare
kong
Bot
force-pushed
the
chore/sync-openapi
branch
from
October 5, 2026 22:54
0d69f5d to
b463e46
Compare
kong
Bot
force-pushed
the
chore/sync-openapi
branch
2 times, most recently
from
October 6, 2026 20:37
be161cb to
d30c70a
Compare
kong
Bot
force-pushed
the
chore/sync-openapi
branch
from
October 7, 2026 02:14
d30c70a to
5854336
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
API change report
Public API
New Endpoints: 17
POST /mcp
GET /openapi.json
HEAD /openapi.json
GET /openapi.yaml
HEAD /openapi.yaml
GET /projects/{id}/access-tokens
POST /projects/{id}/access-tokens
GET /projects/{id}/access-tokens/usage
DELETE /projects/{id}/access-tokens/{tokenId}
GET /projects/{id}/access-tokens/{tokenId}
GET /projects/{id}/access-tokens/{tokenId}/usage
GET /projects/{id}/durable-functions/{functionId}/executions/{executionId}/operations
PUT /projects/{id}/frontend-shared-variables
GET /projects/{id}/frontends/{frontendId}/function-routes
POST /projects/{id}/frontends/{frontendId}/function-routes
DELETE /projects/{id}/frontends/{frontendId}/function-routes/{routeId}
PUT /projects/{id}/frontends/{frontendId}/function-routes/{routeId}
Deleted Endpoints: None
Modified Endpoints: 166
POST /auth/signin
Set
session_modetocookieto request HttpOnly refresh-tokenstorage. Cookie mode is honored only for an exact, credentialed CORS
origin on the same schemeful site as this API. Otherwise the response
retains the refresh token in its body.
' to 'Authenticate with email and password. Requires an anon key.
Set
session_modetocookieto request HttpOnly refresh-tokenstorage. Cookie mode is honored only for an exact, credentialed CORS
origin on the same schemeful site as this API. Otherwise the response
retains the refresh token in its body. A frontend on its default
Volcano URL is cross-site with this API and so always gets the body
token.
'
GET /databases/regions
POST /databases/{databaseName}/branches/{branchName}/query/delete
POST /databases/{databaseName}/branches/{branchName}/query/insert
POST /databases/{databaseName}/branches/{branchName}/query/ping
POST /databases/{databaseName}/branches/{branchName}/query/select
Authentication: Requires auth user access token (from signup/signin)
Row-Level Security: Automatically enforced - you see only data you have access to
Use Cases:
Note: For complex queries (JOINs, CTEs), use Lambda functions with direct SQL
Branch-targeted. Runs against the named branch instead of the parent
database, using the branch's own credentials. The branch must be
activeand unexpired. Nothing about this request can reach the parent's data.
' to 'Query your database using a simple REST API - no SQL required!
Authentication: Requires auth user access token (from signup/signin)
Row-Level Security: Automatically enforced - you see only data you have access to
Use Cases:
Note: For complex queries (JOINs, CTEs), use a function with direct SQL
Branch-targeted. Runs against the named branch instead of the parent
database, using the branch's own credentials. The branch must be
activeand unexpired. Nothing about this request can reach the parent's data.
'
POST /databases/{databaseName}/branches/{branchName}/query/update
POST /databases/{databaseName}/query/delete
POST /databases/{databaseName}/query/insert
POST /databases/{databaseName}/query/ping
POST /databases/{databaseName}/query/select
POST /databases/{databaseName}/query/update
GET /deployments
POST /durable-functions/{functionId}/executions
credential, and returns its handle.
This is the durable counterpart of
POST /functions/{functionId}/invoke,and it is the endpoint an application calls. Like that one, it is not
project-scoped: an anon key, a service key and an auth user token each
carry their own project. The project-scoped collection under
/projects/{id}/durable-functions/...remains the owner's managementsurface.
With a service key or an auth user token: any durable function in
the project.
With an anon key: requires the
functions.invokepermission, andthe function must have
is_public: true.Starting is all this endpoint does. Reading a result or stopping an
execution requires the project owner's token, because an anon key is
shared by everyone who loads the page and an execution is addressed by
id alone.
Send
X-Volcano-Execution-Nameto make the start idempotent: repeatinga start with the same name returns the existing execution instead of
beginning a second one.
Each execution counts once against the project's durable execution
allowance, however many times the start is retried under the same
execution name, and the number in flight at once is capped by the plan.
The operations the execution performs are counted against the durable
operations allowance when it finishes.
' to 'Starts an execution of a durable function using an application
credential, and returns its handle.
This is the durable counterpart of
POST /functions/{functionId}/invoke,and it is the endpoint an application calls. Like that one, it is not
project-scoped: an anon key, a service key and an auth user token each
carry their own project. The project-scoped collection under
/projects/{id}/durable-functions/...remains the owner's managementsurface.
With a service key: any durable function in the project.
With an auth user token: a durable function whose
visibilityisauthenticatedorpublic.With an anon key: requires the
functions.invokepermission, andthe function must have
visibility: public.A
privatedurable function answers every credential but a service keyexactly as a missing one, with 404.
Starting is all this endpoint does. Reading a result or stopping an
execution requires the project owner's token, because an anon key is
shared by everyone who loads the page and an execution is addressed by
id alone.
Send
X-Volcano-Execution-Nameto make the start idempotent: repeatinga start with the same name returns the existing execution instead of
beginning a second one.
Each execution counts once against the project's durable execution
allowance, however many times the start is retried under the same
execution name, and the number in flight at once is capped by the plan.
The operations the execution performs are counted against the durable
operations allowance when it finishes.
'
pendingcovers the window between theplatform reserving the execution name and the function accepting the
start, and has no counterpart once the execution is under way.
succeeded,failed,timed_out,stoppedandunknownareterminal.
unknownmeans the platform lost track of the execution's outcome: itwas never seen to finish and is no longer reported, so no result or
error can be given for it. It is terminal because nothing can settle it
later, and it is rare — treat it as an outcome to retry under a new
name rather than a state to wait on.
completed_aton anunknownexecution is when the platform gave up, not when the work ended.
' to 'Lifecycle state of an execution.
pendingcovers the window between theplatform reserving the execution name and the function accepting the
start, and has no counterpart once the execution is under way.
succeeded,failed,timed_out,stoppedandunknownareterminal.
unknownmeans the execution's outcome cannot be established, so noresult or error can be given for it. Either it was under way and was
never seen to finish, or its start failed with a
500without theplatform establishing whether the execution began — which is why a
name whose start returned an error can later read as
unknownratherthan not being found. It is terminal because nothing can settle it
later, and it is rare — treat it as an outcome to retry rather than a
state to wait on. A retry under the same name picks this execution back
up instead of starting a second one, and needs a free concurrency slot
because an
unknownexecution has given its own up.completed_atonan
unknownexecution is when the platform gave up, not when the workended.
'
functions.invoke, the function is not public,or the request's origin is refused by the project's CORS policy.
' to 'The anon key lacks
functions.invokeor the function isauthenticated, or the request's origin is refused by the project'sCORS policy.
'
id and for a durable function in another project, so the response
cannot be used to tell those apart.
' to 'Durable function not found. Also returned for a standard function's
id, for a durable function in another project, and for a
privateone to any credential but a service key, so the response cannot be
used to tell those apart.
'
usage limit service could not be reached to charge the start. The
first is returned by a deployment that has no durable execution
engine, such as a local one, and is not retryable there; the second
is transient.
' to 'Durable execution is not available in this environment, or the
plan terms for the start could not be read. The first means the
capability is paused or this deployment cannot serve it, so it is
not one to retry in a loop; the second is transient.
'
GET /functions/resolve
SDKs use this endpoint internally to invoke by function name while routing by function ID.
With Service Key:
With Auth User Token:
With Anon Key:
functions.invokeis_public: true' to 'Resolves a DNS-safe function name to its function ID and invocation URL within the caller's project.
SDKs use this endpoint internally to invoke by function name while routing by function ID.
Invoke the returned
invoke_urlas-is. It does not share a domain with the API, so a hostbuilt from the API URL will not reach the function. When the deployment serves no public
invocation domain, as in local development,
invoke_urlis omitted and callers invokethrough
POST /functions/{functionId}/invoke.With Service Key:
With Auth User Token:
authenticatedandpublicfunctionsprivatefunction answers 404, exactly as a missing oneWith Anon Key:
functions.invokevisibility: public; any other answers 404'
functions.invokepermission for anon key' to 'Forbidden - CORS blocked, or missingfunctions.invokepermissionfor anon key
'
function is never resolvable here: it is started through
POST /durable-functions/{functionId}/executions, not invoked.' to 'Function not found. Also returned for a
privatefunction with anauth user token, and a non-public one with an anon key. A durable
function is never resolvable here: it is started through
POST /durable-functions/{functionId}/executions, not invoked.'
GET /functions/runtimes
language defaults, and local source packaging metadata for deployments.
This is a public endpoint that doesn't require authentication.
' to 'Returns the public function runtime catalog: every runtime a deploy accepts, its display
label for runtime pickers, language defaults, durable capability, and local source packaging
metadata for deployments.
This is a public endpoint that doesn't require authentication.
'
POST /functions/{functionId}/invoke
With Service Key (admin/background operations):
With Auth User Token (user-facing):
__volcano_authcontext:With Anon Key (public function only):
functions.invokeis_public: true__volcano_auth)Transport and CORS:
POST
{payload: ...}contract, including for functions whose DNS ingress isconfigured in HTTP mode.
https://{functionId}.functions.<domain>/./. HTTP-mode DNS ingress accepts GET,HEAD, POST, PUT, PATCH, and DELETE at
/and nested paths.POST, OPTIONS. HTTP-mode DNSpreflight advertises
GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS.http_auth_mode: noneapplies only to public HTTP-mode DNS ingress; thisdirect operation always requires a Volcano credential.
Durable functions are not invocable here. A durable function's id
answers 404, whatever its visibility, because a synchronous call would
run it with no execution record, no idempotency and no concurrency
accounting. Start one with
POST /durable-functions/{functionId}/executions.' to 'Invoke a function. The function's
visibilitydecides which credentialsmay call it, and the function does not run for any other. A
privatefunction answers every credential but a service key exactly as a
missing one, with 404, so its name and id cannot be discovered; an anon
key on an
authenticatedfunction gets 403. An SDK calling by nameresolves it first through
GET /functions/resolve, which answers thatanon key with 404 instead.
With Service Key (admin/background operations, every visibility):
With Auth User Token (user-facing,
authenticatedorpublicfunctions):__volcano_authcontext:With Anon Key (
publicfunctions only):functions.invokevisibility: public__volcano_auth)Transport and CORS:
POST
{payload: ...}contract, including for functions whose DNS ingress isconfigured in HTTP mode.
invoke_url. It is on adifferent domain from this API, so it cannot be derived from the API host.
/. HTTP-mode DNS ingress accepts GET,HEAD, POST, PUT, PATCH, and DELETE at
/and nested paths.POST, OPTIONS. HTTP-mode DNSpreflight advertises
GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS.http_auth_mode: noneapplies only to public HTTP-mode DNS ingress; thisdirect operation always requires a Volcano credential.
Durable functions are not invocable here. A durable function's id
answers 404, whatever its visibility, because a synchronous call would
run it with no execution record, no idempotency and no concurrency
accounting. Start one with
POST /durable-functions/{functionId}/executions.'
functions.invoke, or private function with anon key' to 'Forbidden - CORS blocked, missingfunctions.invoke, or an anon keyon an
authenticatedfunction'
privatefunction to anycredential but a service key.
'
GET /projects
POST /projects
DELETE /projects/{id}
GET /projects/{id}
PATCH /projects/{id}
GET /projects/{id}/anon-keys
POST /projects/{id}/anon-keys
DELETE /projects/{id}/anon-keys/{keyId}
GET /projects/{id}/anon-keys/{keyId}
POST /projects/{id}/anon-keys/{keyId}/regenerate
POST /projects/{id}/anon-keys/{keyId}/set-default
GET /projects/{id}/auth/config
PUT /projects/{id}/auth/config
POST /projects/{id}/auth/config/test-email
GET /projects/{id}/auth/hosted-pages/{pageType}
PUT /projects/{id}/auth/hosted-pages/{pageType}
GET /projects/{id}/auth/insights
zero-filled signup and successful sign-in counts for an inclusive UTC
date range. Weeks start on Monday. Sign-in counts and active-user
activity begin when collection is deployed. Historical signup counts
are backfilled from users present at deployment. Token refreshes affect
active users but not the sign-in series.
' to 'Returns current and deleted auth-user totals, rolling 24-hour and 30-day
active users, and zero-filled signup, deletion, net-growth, and successful
sign-in counts for an inclusive UTC date range. Weeks start on Monday.
Signups remain counted after deletion; net growth is signups minus
deletions. Deleted users contribute to active counts until their last
activity leaves the rolling window. Token refreshes affect active users
but not the sign-in series. Collection starts at deployment, with signup
history backfilled from accounts still present then. Earlier hard-deleted
accounts cannot be recovered.
'
GET /projects/{id}/auth/methods
PUT /projects/{id}/auth/methods
GET /projects/{id}/auth/pages/appearance
DELETE /projects/{id}/auth/pages/theme
PUT /projects/{id}/auth/pages/theme
DELETE /projects/{id}/auth/pages/{pageType}/layout
PUT /projects/{id}/auth/pages/{pageType}/layout
POST /projects/{id}/auth/pages/{pageType}/preview
GET /projects/{id}/auth/users
DELETE /projects/{id}/auth/users/{userId}
GET /projects/{id}/auth/users/{userId}
POST /projects/{id}/auth/users/{userId}/ban
Description changed from 'Bans a user temporarily or permanently. Banned users cannot sign in
and all their active sessions are immediately revoked.
Omit
banned_untilfor a permanent banProvide
banned_untilISO timestamp for a temporary ban' to 'Bans a user temporarily or permanently. Banned users cannot sign in
and all their active sessions are immediately revoked.
Omitting banned_until clears any previous expiry. Deleted accounts cannot be banned.
Omit
banned_untilfor a permanent banProvide
banned_untilISO timestamp for a temporary ban'
Responses changed
Security changed
DELETE /projects/{id}/auth/users/{userId}/sessions
GET /projects/{id}/auth/users/{userId}/sessions
DELETE /projects/{id}/auth/users/{userId}/sessions/{sessionId}
POST /projects/{id}/auth/users/{userId}/unban
The user's status is set back to 'active'.
' to 'Removes a ban from a user, restoring their ability to sign in.
The user's status is set back to 'active'. Deleted accounts cannot be restored.
'
GET /projects/{id}/config
declarative manifest. Returns JSON by default. Request the canonical
volcano-config.yaml rendering with
Accept: application/yamlor?format=yaml; the YAML is returned verbatim as the raw response body(
Content-Type: application/yaml) and is meant to be saved as-is.Variable values and write-only secrets (SMTP password, OAuth client secrets, TLS material)
are omitted from the export; shared_variables contains names only; the YAML rendering adds a header comment
describing how to set them via CLI environment interpolation.
' to 'Exports the project's current user-facing configuration as a
declarative manifest. Returns JSON by default. Request the canonical
volcano-config.yaml rendering with
Accept: application/yamlor?format=yaml; the YAML is returned verbatim as the raw response body(
Content-Type: application/yaml) and is meant to be saved as-is.Variable values and write-only secrets (SMTP password, OAuth client secrets, TLS material)
are omitted from the export; shared_variables and frontend_shared_variables contain names only; the YAML rendering adds a header comment
describing how to set them via CLI environment interpolation.
'
noneis valid only for publicHTTP-mode functions and is intended for externally signed webhooks.
' to 'Authentication applied by the HTTP ingress.
noneis valid only forHTTP-mode functions with
visibility: publicand is intended forexternally signed webhooks.
'
visibility:truemeanspublicandfalsemeansauthenticated, notprivate, so an entry left atfalseappliesauthenticatedon every apply; declarevisibility: privateto keep a function private. Declaring bothwith different meanings is an error. Exports write
visibilityonly.
'
PUT /projects/{id}/config
noneis valid only for publicHTTP-mode functions and is intended for externally signed webhooks.
' to 'Authentication applied by the HTTP ingress.
noneis valid only forHTTP-mode functions with
visibility: publicand is intended forexternally signed webhooks.
'
visibility:truemeanspublicandfalsemeansauthenticated, notprivate, so an entry left atfalseappliesauthenticatedon every apply; declarevisibility: privateto keep a function private. Declaring bothwith different meanings is an error. Exports write
visibilityonly.
'
GET /projects/{id}/databases
POST /projects/{id}/databases
Each project can hold 1 database on Hobby and up to 10,000 on Superagent.
Requests over the plan's cap return 403.
' to 'Creates a PostgreSQL database in the project.
Each project can hold 1 database on HOBBY and up to 10,000 on SUPERAGENT.
Requests over the plan's cap return 403.
'
environment runs in, so read them from
GET /databases/regionsratherthan hardcoding a list. A region the environment does not offer is
rejected with 400.
' to 'Region for database hosting, such as
us-east-1. The accepted valuesare the regions this environment runs in, so read them from
GET /databases/regionsrather than hardcoding a list. A region theenvironment does not offer is rejected with 400. Region IDs issued by
earlier versions of the API are still accepted.
'
DELETE /projects/{id}/databases/{databaseName}
GET /projects/{id}/databases/{databaseName}
Report truncated; see the source commit for the complete contract diff.
Validation