Skip to content

chore(api): sync OpenAPI contract - #2

Draft
kong[bot] wants to merge 1 commit into
mainfrom
chore/sync-openapi
Draft

kong[bot] wants to merge 1 commit into
mainfrom
chore/sync-openapi

Conversation

@kong

@kong kong Bot commented Aug 28, 2026 •

Copy link
Copy Markdown

Summary

API change report

Public API

New Endpoints: 17


POST /mcp
GET /openapi.json
HEAD /openapi.json
GET /openapi.yaml
HEAD /openapi.yaml
GET /projects/{id}/access-tokens
POST /projects/{id}/access-tokens
GET /projects/{id}/access-tokens/usage
DELETE /projects/{id}/access-tokens/{tokenId}
GET /projects/{id}/access-tokens/{tokenId}
GET /projects/{id}/access-tokens/{tokenId}/usage
GET /projects/{id}/durable-functions/{functionId}/executions/{executionId}/operations
PUT /projects/{id}/frontend-shared-variables
GET /projects/{id}/frontends/{frontendId}/function-routes
POST /projects/{id}/frontends/{frontendId}/function-routes
DELETE /projects/{id}/frontends/{frontendId}/function-routes/{routeId}
PUT /projects/{id}/frontends/{frontendId}/function-routes/{routeId}

Deleted Endpoints: None


Modified Endpoints: 166


POST /auth/signin

  • Description changed from 'Authenticate with email and password. Requires an anon key.

Set session_mode to cookie to request HttpOnly refresh-token
storage. Cookie mode is honored only for an exact, credentialed CORS
origin on the same schemeful site as this API. Otherwise the response
retains the refresh token in its body.
' to 'Authenticate with email and password. Requires an anon key.

Set session_mode to cookie to request HttpOnly refresh-token
storage. Cookie mode is honored only for an exact, credentialed CORS
origin on the same schemeful site as this API. Otherwise the response
retains the refresh token in its body. A frontend on its default
Volcano URL is cross-site with this API and so always gets the body
token.
'

GET /databases/regions

  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Items changed
              • Properties changed
                • Modified property: id
                  • Example changed from 'aws-us-east-1' to 'us-east-1'

POST /databases/{databaseName}/branches/{branchName}/query/delete

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

POST /databases/{databaseName}/branches/{branchName}/query/insert

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

POST /databases/{databaseName}/branches/{branchName}/query/ping

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

POST /databases/{databaseName}/branches/{branchName}/query/select

  • Description changed from 'Query your database using a simple REST API - no SQL required!

Authentication: Requires auth user access token (from signup/signin)

Row-Level Security: Automatically enforced - you see only data you have access to

Use Cases:

  • Query from browser/mobile apps
  • Simple data retrieval
  • Filtered searches with sorting and pagination

Note: For complex queries (JOINs, CTEs), use Lambda functions with direct SQL

Branch-targeted. Runs against the named branch instead of the parent
database, using the branch's own credentials. The branch must be active
and unexpired. Nothing about this request can reach the parent's data.
' to 'Query your database using a simple REST API - no SQL required!

Authentication: Requires auth user access token (from signup/signin)

Row-Level Security: Automatically enforced - you see only data you have access to

Use Cases:

  • Query from browser/mobile apps
  • Simple data retrieval
  • Filtered searches with sorting and pagination

Note: For complex queries (JOINs, CTEs), use a function with direct SQL

Branch-targeted. Runs against the named branch instead of the parent
database, using the branch's own credentials. The branch must be active
and unexpired. Nothing about this request can reach the parent's data.
'

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

POST /databases/{databaseName}/branches/{branchName}/query/update

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

POST /databases/{databaseName}/query/delete

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

POST /databases/{databaseName}/query/insert

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

POST /databases/{databaseName}/query/ping

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

POST /databases/{databaseName}/query/select

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

POST /databases/{databaseName}/query/update

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

GET /deployments

  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • Modified property: data
                • Items changed
                  • Properties changed
                    • Deleted property: artifact_version

POST /durable-functions/{functionId}/executions

  • Description changed from 'Starts an execution of a durable function using an application
    credential, and returns its handle.

This is the durable counterpart of POST /functions/{functionId}/invoke,
and it is the endpoint an application calls. Like that one, it is not
project-scoped: an anon key, a service key and an auth user token each
carry their own project. The project-scoped collection under
/projects/{id}/durable-functions/... remains the owner's management
surface.

With a service key or an auth user token: any durable function in
the project.

With an anon key: requires the functions.invoke permission, and
the function must have is_public: true.

Starting is all this endpoint does. Reading a result or stopping an
execution requires the project owner's token, because an anon key is
shared by everyone who loads the page and an execution is addressed by
id alone.

Send X-Volcano-Execution-Name to make the start idempotent: repeating
a start with the same name returns the existing execution instead of
beginning a second one.

Each execution counts once against the project's durable execution
allowance, however many times the start is retried under the same
execution name, and the number in flight at once is capped by the plan.
The operations the execution performs are counted against the durable
operations allowance when it finishes.
' to 'Starts an execution of a durable function using an application
credential, and returns its handle.

This is the durable counterpart of POST /functions/{functionId}/invoke,
and it is the endpoint an application calls. Like that one, it is not
project-scoped: an anon key, a service key and an auth user token each
carry their own project. The project-scoped collection under
/projects/{id}/durable-functions/... remains the owner's management
surface.

With a service key: any durable function in the project.

With an auth user token: a durable function whose visibility is
authenticated or public.

With an anon key: requires the functions.invoke permission, and
the function must have visibility: public.

A private durable function answers every credential but a service key
exactly as a missing one, with 404.

Starting is all this endpoint does. Reading a result or stopping an
execution requires the project owner's token, because an anon key is
shared by everyone who loads the page and an execution is addressed by
id alone.

Send X-Volcano-Execution-Name to make the start idempotent: repeating
a start with the same name returns the existing execution instead of
beginning a second one.

Each execution counts once against the project's durable execution
allowance, however many times the start is retried under the same
execution name, and the number in flight at once is capped by the plan.
The operations the execution performs are counted against the durable
operations allowance when it finishes.
'

  • Responses changed
    • Modified response: 202
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • Modified property: status
                • Description changed from 'Lifecycle state of an execution. pending covers the window between the
                  platform reserving the execution name and the function accepting the
                  start, and has no counterpart once the execution is under way.
                  succeeded, failed, timed_out, stopped and unknown are
                  terminal.

unknown means the platform lost track of the execution's outcome: it
was never seen to finish and is no longer reported, so no result or
error can be given for it. It is terminal because nothing can settle it
later, and it is rare — treat it as an outcome to retry under a new
name rather than a state to wait on. completed_at on an unknown
execution is when the platform gave up, not when the work ended.
' to 'Lifecycle state of an execution. pending covers the window between the
platform reserving the execution name and the function accepting the
start, and has no counterpart once the execution is under way.
succeeded, failed, timed_out, stopped and unknown are
terminal.

unknown means the execution's outcome cannot be established, so no
result or error can be given for it. Either it was under way and was
never seen to finish, or its start failed with a 500 without the
platform establishing whether the execution began — which is why a
name whose start returned an error can later read as unknown rather
than not being found. It is terminal because nothing can settle it
later, and it is rare — treat it as an outcome to retry rather than a
state to wait on. A retry under the same name picks this execution back
up instead of starting a second one, and needs a free concurrency slot
because an unknown execution has given its own up. completed_at on
an unknown execution is when the platform gave up, not when the work
ended.
'

  • Modified response: 403
    • Description changed from 'The anon key lacks functions.invoke, the function is not public,
      or the request's origin is refused by the project's CORS policy.
      ' to 'The anon key lacks functions.invoke or the function is
      authenticated, or the request's origin is refused by the project's
      CORS policy.
      '
  • Modified response: 404
    • Description changed from 'Durable function not found. Also returned for a standard function's
      id and for a durable function in another project, so the response
      cannot be used to tell those apart.
      ' to 'Durable function not found. Also returned for a standard function's
      id, for a durable function in another project, and for a private
      one to any credential but a service key, so the response cannot be
      used to tell those apart.
      '
  • Modified response: 503
    • Description changed from 'Durable execution is not available in this environment, or the
      usage limit service could not be reached to charge the start. The
      first is returned by a deployment that has no durable execution
      engine, such as a local one, and is not retryable there; the second
      is transient.
      ' to 'Durable execution is not available in this environment, or the
      plan terms for the start could not be read. The first means the
      capability is paused or this deployment cannot serve it, so it is
      not one to retry in a loop; the second is transient.
      '

GET /functions/resolve

  • Description changed from 'Resolves a DNS-safe function name to its function ID within the caller's project.

SDKs use this endpoint internally to invoke by function name while routing by function ID.

With Service Key:

  • Allowed

With Auth User Token:

  • Allowed

With Anon Key:

  • Requires anon key permission: functions.invoke
  • Function must have is_public: true
    ' to 'Resolves a DNS-safe function name to its function ID and invocation URL within the caller's project.

SDKs use this endpoint internally to invoke by function name while routing by function ID.
Invoke the returned invoke_url as-is. It does not share a domain with the API, so a host
built from the API URL will not reach the function. When the deployment serves no public
invocation domain, as in local development, invoke_url is omitted and callers invoke
through POST /functions/{functionId}/invoke.

With Service Key:

  • Allowed

With Auth User Token:

  • Allowed for authenticated and public functions
  • A private function answers 404, exactly as a missing one

With Anon Key:

  • Requires anon key permission: functions.invoke
  • Function must have visibility: public; any other answers 404
    '
  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • New property: invoke_url
    • Modified response: 403
      • Description changed from 'Forbidden - CORS blocked or missing functions.invoke permission for anon key' to 'Forbidden - CORS blocked, or missing functions.invoke permission
        for anon key
        '
    • Modified response: 404
      • Description changed from 'Function not found (or private function with anon key). A durable
        function is never resolvable here: it is started through
        POST /durable-functions/{functionId}/executions, not invoked.
        ' to 'Function not found. Also returned for a private function with an
        auth user token, and a non-public one with an anon key. A durable
        function is never resolvable here: it is started through
        POST /durable-functions/{functionId}/executions, not invoked.
        '

GET /functions/runtimes

  • Description changed from 'Returns the public function runtime catalog used by CLI clients to select supported runtimes,
    language defaults, and local source packaging metadata for deployments.
    This is a public endpoint that doesn't require authentication.
    ' to 'Returns the public function runtime catalog: every runtime a deploy accepts, its display
    label for runtime pickers, language defaults, durable capability, and local source packaging
    metadata for deployments.
    This is a public endpoint that doesn't require authentication.
    '
  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • Modified property: runtimes
                • Items changed
                  • Required changed
                    • New required property: label
                  • Properties changed
                    • New property: label

POST /functions/{functionId}/invoke

  • Description changed from 'Invoke a serverless function.

With Service Key (admin/background operations):

  • Use for background jobs, webhooks, cron, admin operations
  • Function receives payload only (no user context)
  • Database queries bypass RLS (admin access)

With Auth User Token (user-facing):

  • Use for user-initiated actions
  • Function receives payload + __volcano_auth context:
    {
      user_id: "uuid",
      email: "user@example.com",
      project_id: "uuid",
      role: "authenticated" or "anonymous"
    }
  • Database queries enforce RLS (user-scoped data)

With Anon Key (public function only):

  • Requires anon key permission: functions.invoke
  • Function must have is_public: true
  • Function receives payload only (no __volcano_auth)

Transport and CORS:

  • This operation is the authenticated direct RPC endpoint and always uses the
    POST {payload: ...} contract, including for functions whose DNS ingress is
    configured in HTTP mode.
  • The geo-routed DNS ingress is https://{functionId}.functions.<domain>/.
  • RPC-mode DNS ingress accepts POST at /. HTTP-mode DNS ingress accepts GET,
    HEAD, POST, PUT, PATCH, and DELETE at / and nested paths.
  • Direct and RPC-mode CORS preflight advertises POST, OPTIONS. HTTP-mode DNS
    preflight advertises GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS.
  • http_auth_mode: none applies only to public HTTP-mode DNS ingress; this
    direct operation always requires a Volcano credential.

Durable functions are not invocable here. A durable function's id
answers 404, whatever its visibility, because a synchronous call would
run it with no execution record, no idempotency and no concurrency
accounting. Start one with
POST /durable-functions/{functionId}/executions.
' to 'Invoke a function. The function's visibility decides which credentials
may call it, and the function does not run for any other. A private
function answers every credential but a service key exactly as a
missing one, with 404, so its name and id cannot be discovered; an anon
key on an authenticated function gets 403. An SDK calling by name
resolves it first through GET /functions/resolve, which answers that
anon key with 404 instead.

With Service Key (admin/background operations, every visibility):

  • Use for background jobs, webhooks, cron, admin operations
  • Function receives payload only (no user context)
  • Database queries bypass RLS (admin access)

With Auth User Token (user-facing, authenticated or public functions):

  • Use for user-initiated actions
  • Includes users from anonymous sign-ins
  • Function receives payload + __volcano_auth context:
    {
      user_id: "uuid",
      email: "user@example.com",
      project_id: "uuid",
      role: "authenticated" or "anonymous"
    }
  • Database queries enforce RLS (user-scoped data)

With Anon Key (public functions only):

  • Requires anon key permission: functions.invoke
  • Function must have visibility: public
  • Function receives payload only (no __volcano_auth)

Transport and CORS:

  • This operation is the authenticated direct RPC endpoint and always uses the
    POST {payload: ...} contract, including for functions whose DNS ingress is
    configured in HTTP mode.
  • The geo-routed DNS ingress is the function's invoke_url. It is on a
    different domain from this API, so it cannot be derived from the API host.
  • RPC-mode DNS ingress accepts POST at /. HTTP-mode DNS ingress accepts GET,
    HEAD, POST, PUT, PATCH, and DELETE at / and nested paths.
  • Direct and RPC-mode CORS preflight advertises POST, OPTIONS. HTTP-mode DNS
    preflight advertises GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS.
  • http_auth_mode: none applies only to public HTTP-mode DNS ingress; this
    direct operation always requires a Volcano credential.

Durable functions are not invocable here. A durable function's id
answers 404, whatever its visibility, because a synchronous call would
run it with no execution record, no idempotency and no concurrency
accounting. Start one with
POST /durable-functions/{functionId}/executions.
'

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms
    • Modified response: 403
      • Description changed from 'Forbidden - CORS blocked, missing functions.invoke, or private function with anon key' to 'Forbidden - CORS blocked, missing functions.invoke, or an anon key
        on an authenticated function
        '
    • Modified response: 404
      • Description changed from 'Function not found' to 'Function not found. Also returned for a private function to any
        credential but a service key.
        '
    • Modified response: default
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

GET /projects

  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • Modified property: data
                • Items changed
                  • Properties changed
                    • New property: template_installation
                    • Deleted property: aws_application_name
                    • Modified property: plan
                    • Description changed from 'Public plan name; FREE and PRO are accepted from older Hosting responses.' to 'Plan name applied to the project when available.'
                    • Deleted enum values: [FREE PRO]

POST /projects

  • Request body changed
    • Content changed
      • Modified media type: application/json
        • Schema changed
          • Properties changed
            • New property: initialPrompt
            • New property: template_id
  • Responses changed
    • New response: 503
    • Modified response: 201
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • New property: template_installation
              • Deleted property: aws_application_name
              • Modified property: plan
                • Description changed from 'Public plan name; FREE and PRO are accepted from older Hosting responses.' to 'Plan name applied to the project when available.'
                • Deleted enum values: [FREE PRO]

DELETE /projects/{id}

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}

  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • New property: template_installation
              • Deleted property: aws_application_name
              • Modified property: plan
                • Description changed from 'Public plan name; FREE and PRO are accepted from older Hosting responses.' to 'Plan name applied to the project when available.'
                • Deleted enum values: [FREE PRO]
  • Security changed
    • New security requirements: ProjectAccessToken

PATCH /projects/{id}

  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • New property: template_installation
              • Deleted property: aws_application_name
              • Modified property: plan
                • Description changed from 'Public plan name; FREE and PRO are accepted from older Hosting responses.' to 'Plan name applied to the project when available.'
                • Deleted enum values: [FREE PRO]
    • Modified response: 403
      • Description changed from 'Forbidden (for example, selecting subset regions on non-SUPERAGENT plan)' to 'Forbidden (for example, selecting subset regions on plan other than SUPERAGENT)'
  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/anon-keys

  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/anon-keys

  • Security changed
    • New security requirements: ProjectAccessToken

DELETE /projects/{id}/anon-keys/{keyId}

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/anon-keys/{keyId}

  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/anon-keys/{keyId}/regenerate

  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/anon-keys/{keyId}/set-default

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/auth/config

  • Security changed
    • New security requirements: ProjectAccessToken

PUT /projects/{id}/auth/config

  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/auth/config/test-email

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/auth/hosted-pages/{pageType}

  • Security changed
    • New security requirements: ProjectAccessToken

PUT /projects/{id}/auth/hosted-pages/{pageType}

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/auth/insights

  • Description changed from 'Returns current auth-user totals, rolling 30-day active users, and
    zero-filled signup and successful sign-in counts for an inclusive UTC
    date range. Weeks start on Monday. Sign-in counts and active-user
    activity begin when collection is deployed. Historical signup counts
    are backfilled from users present at deployment. Token refreshes affect
    active users but not the sign-in series.
    ' to 'Returns current and deleted auth-user totals, rolling 24-hour and 30-day
    active users, and zero-filled signup, deletion, net-growth, and successful
    sign-in counts for an inclusive UTC date range. Weeks start on Monday.
    Signups remain counted after deletion; net growth is signups minus
    deletions. Deleted users contribute to active counts until their last
    activity leaves the rolling window. Token refreshes affect active users
    but not the sign-in series. Collection starts at deployment, with signup
    history backfilled from accounts still present then. Earlier hard-deleted
    accounts cannot be recovered.
    '
  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • Modified property: series
                • Items changed
                  • Required changed
                    • New required property: deletions
                    • New required property: net_growth
                  • Properties changed
                    • New property: deletions
                    • New property: net_growth
                    • Modified property: signups
                    • Description changed from 'Accounts created during the bucket.' to 'Registrations during the bucket. Subsequent deletion does not subtract from this count. Historical counts removed before deletion-history collection cannot be reconstructed.'
              • Modified property: summary
                • Required changed
                  • New required property: active_users_1d
                  • New required property: deleted_users
                • Properties changed
                  • New property: active_users_1d
                  • New property: deleted_users
                  • Modified property: active_users_30d
                    • Description changed from 'Users with a successful session creation or refresh in the trailing 30 days since activity collection was deployed.' to 'Distinct users with a successful session creation or refresh in the trailing 30 days, including activity before account deletion.'
                  • Modified property: total_users
                    • Description changed from 'Current auth-user count, matching the auth-user list total.' to 'Current auth-user count, excluding accounts with deleted status.'
          • Example changed from map[observed_at:2026-07-20T18:00:00Z project_id:4f165080-a931-4e03-b3bd-41c45c3f0058 series:[map[bucket_start:2026-07-20 is_partial:true signins:97 signups:12]] summary:map[active_users_30d:418 total_users:1234] window:map[from:2026-06-21 interval:day to:2026-07-20]] to map[observed_at:2026-07-20T18:00:00Z project_id:4f165080-a931-4e03-b3bd-41c45c3f0058 series:[map[bucket_start:2026-07-20 deletions:3 is_partial:true net_growth:9 signins:97 signups:12]] summary:map[active_users_1d:83 active_users_30d:418 deleted_users:42 total_users:1234] window:map[from:2026-06-21 interval:day to:2026-07-20]]
  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/auth/methods

  • Security changed
    • New security requirements: ProjectAccessToken

PUT /projects/{id}/auth/methods

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/auth/pages/appearance

  • Security changed
    • New security requirements: ProjectAccessToken

DELETE /projects/{id}/auth/pages/theme

  • Security changed
    • New security requirements: ProjectAccessToken

PUT /projects/{id}/auth/pages/theme

  • Security changed
    • New security requirements: ProjectAccessToken

DELETE /projects/{id}/auth/pages/{pageType}/layout

  • Security changed
    • New security requirements: ProjectAccessToken

PUT /projects/{id}/auth/pages/{pageType}/layout

  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/auth/pages/{pageType}/preview

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/auth/users

  • Security changed
    • New security requirements: ProjectAccessToken

DELETE /projects/{id}/auth/users/{userId}

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/auth/users/{userId}

  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/auth/users/{userId}/ban

  • Description changed from 'Bans a user temporarily or permanently. Banned users cannot sign in
    and all their active sessions are immediately revoked.

  • Omit banned_until for a permanent ban

  • Provide banned_until ISO timestamp for a temporary ban
    ' to 'Bans a user temporarily or permanently. Banned users cannot sign in
    and all their active sessions are immediately revoked.
    Omitting banned_until clears any previous expiry. Deleted accounts cannot be banned.

  • Omit banned_until for a permanent ban

  • Provide banned_until ISO timestamp for a temporary ban
    '

  • Responses changed

    • New response: 409
  • Security changed

    • New security requirements: ProjectAccessToken

DELETE /projects/{id}/auth/users/{userId}/sessions

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/auth/users/{userId}/sessions

  • Security changed
    • New security requirements: ProjectAccessToken

DELETE /projects/{id}/auth/users/{userId}/sessions/{sessionId}

  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/auth/users/{userId}/unban

  • Description changed from 'Removes a ban from a user, restoring their ability to sign in.
    The user's status is set back to 'active'.
    ' to 'Removes a ban from a user, restoring their ability to sign in.
    The user's status is set back to 'active'. Deleted accounts cannot be restored.
    '
  • Responses changed
    • New response: 409
  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/config

  • Description changed from 'Exports the project's current user-facing configuration as a
    declarative manifest. Returns JSON by default. Request the canonical
    volcano-config.yaml rendering with Accept: application/yaml or
    ?format=yaml; the YAML is returned verbatim as the raw response body
    (Content-Type: application/yaml) and is meant to be saved as-is.
    Variable values and write-only secrets (SMTP password, OAuth client secrets, TLS material)
    are omitted from the export; shared_variables contains names only; the YAML rendering adds a header comment
    describing how to set them via CLI environment interpolation.
    ' to 'Exports the project's current user-facing configuration as a
    declarative manifest. Returns JSON by default. Request the canonical
    volcano-config.yaml rendering with Accept: application/yaml or
    ?format=yaml; the YAML is returned verbatim as the raw response body
    (Content-Type: application/yaml) and is meant to be saved as-is.
    Variable values and write-only secrets (SMTP password, OAuth client secrets, TLS material)
    are omitted from the export; shared_variables and frontend_shared_variables contain names only; the YAML rendering adds a header comment
    describing how to set them via CLI environment interpolation.
    '
  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • New property: frontend_shared_variables
              • Modified property: databases
                • Items changed
                  • Properties changed
                    • Modified property: region
                    • Description changed from 'Deployed region ID (e.g. aws-us-east-1). Asserted, never written.' to 'Deployed region ID (e.g. us-east-1). Asserted, never written; region IDs issued by earlier versions of the API match too.'
              • Modified property: frontends
                • Items changed
                  • Properties changed
                    • New property: function_routes
                    • New property: variable_scope
                    • New property: variables
              • Modified property: functions
                • Items changed
                  • Properties changed
                    • New property: visibility
                    • Modified property: http_auth_mode
                    • Description changed from 'Authentication applied by the HTTP ingress. none is valid only for public
                      HTTP-mode functions and is intended for externally signed webhooks.
                      ' to 'Authentication applied by the HTTP ingress. none is valid only for
                      HTTP-mode functions with visibility: public and is intended for
                      externally signed webhooks.
                      '
                    • Modified property: public
                    • Description changed from 'Function visibility for anon-key invocation' to 'Deprecated alias for visibility: true means public and
                      false means authenticated, not private, so an entry left at
                      false applies authenticated on every apply; declare
                      visibility: private to keep a function private. Declaring both
                      with different meanings is an error. Exports write visibility
                      only.
                      '
                    • Deprecated changed from false to true
                    • Modified property: variable_scope
                    • Extensions changed
                    • New extension: x-enum-varnames
              • Modified property: variables
                • Items changed
                  • Properties changed
                    • Modified property: name
                    • Description changed from '' to 'Project variable name. Function runtime names such as AWS_REGION are reserved and fail validation; see the environment variables guide for the full list.'
  • Security changed
    • New security requirements: ProjectAccessToken

PUT /projects/{id}/config

  • Request body changed
    • Content changed
      • Modified media type: application/json
        • Schema changed
          • Properties changed
            • New property: frontend_shared_variables
            • Modified property: databases
              • Items changed
                • Properties changed
                  • Modified property: region
                    • Description changed from 'Deployed region ID (e.g. aws-us-east-1). Asserted, never written.' to 'Deployed region ID (e.g. us-east-1). Asserted, never written; region IDs issued by earlier versions of the API match too.'
            • Modified property: frontends
              • Items changed
                • Properties changed
                  • New property: function_routes
                  • New property: variable_scope
                  • New property: variables
            • Modified property: functions
              • Items changed
                • Properties changed
                  • New property: visibility
                  • Modified property: http_auth_mode
                    • Description changed from 'Authentication applied by the HTTP ingress. none is valid only for public
                      HTTP-mode functions and is intended for externally signed webhooks.
                      ' to 'Authentication applied by the HTTP ingress. none is valid only for
                      HTTP-mode functions with visibility: public and is intended for
                      externally signed webhooks.
                      '
                  • Modified property: public
                    • Description changed from 'Function visibility for anon-key invocation' to 'Deprecated alias for visibility: true means public and
                      false means authenticated, not private, so an entry left at
                      false applies authenticated on every apply; declare
                      visibility: private to keep a function private. Declaring both
                      with different meanings is an error. Exports write visibility
                      only.
                      '
                    • Deprecated changed from false to true
                  • Modified property: variable_scope
                    • Extensions changed
                    • New extension: x-enum-varnames
            • Modified property: variables
              • Items changed
                • Properties changed
                  • Modified property: name
                    • Description changed from '' to 'Project variable name. Function runtime names such as AWS_REGION are reserved and fail validation; see the environment variables guide for the full list.'
  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/databases

  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • Modified property: data
                • Items changed
                  • Properties changed
                    • Modified property: region
                    • Example changed from 'aws-us-east-1' to 'us-east-1'
  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/databases

  • Summary changed from 'Create a new serverless PostgreSQL database' to 'Create a new PostgreSQL database'
  • Description changed from 'Creates a serverless PostgreSQL database in the project.
    Each project can hold 1 database on Hobby and up to 10,000 on Superagent.
    Requests over the plan's cap return 403.
    ' to 'Creates a PostgreSQL database in the project.
    Each project can hold 1 database on HOBBY and up to 10,000 on SUPERAGENT.
    Requests over the plan's cap return 403.
    '
  • Request body changed
    • Content changed
      • Modified media type: application/json
        • Schema changed
          • Properties changed
            • Modified property: region
              • Description changed from 'Region for database hosting. The accepted values are the regions this
                environment runs in, so read them from GET /databases/regions rather
                than hardcoding a list. A region the environment does not offer is
                rejected with 400.
                ' to 'Region for database hosting, such as us-east-1. The accepted values
                are the regions this environment runs in, so read them from
                GET /databases/regions rather than hardcoding a list. A region the
                environment does not offer is rejected with 400. Region IDs issued by
                earlier versions of the API are still accepted.
                '
              • Example changed from 'aws-us-east-1' to 'us-east-1'
  • Responses changed
    • Modified response: 201
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • Modified property: region
                • Example changed from 'aws-us-east-1' to 'us-east-1'
  • Security changed
    • New security requirements: ProjectAccessToken

DELETE /projects/{id}/databases/{databaseName}

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/databases/{databaseName}

  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed

Report truncated; see the source commit for the complete contract diff.

Validation

@kong
kong Bot force-pushed the chore/sync-openapi branch from 7cd039d to b69cdc1 Compare August 28, 2026 13:58
@kong
kong Bot force-pushed the chore/sync-openapi branch 4 times, most recently from ebe76ec to 5660716 Compare August 30, 2026 12:25
@kong
kong Bot force-pushed the chore/sync-openapi branch from 5660716 to 697020d Compare September 10, 2026 22:00
@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@kong
kong Bot force-pushed the chore/sync-openapi branch 13 times, most recently from ebaec87 to 2891cbb Compare September 17, 2026 18:04
@kong
kong Bot force-pushed the chore/sync-openapi branch 8 times, most recently from 2768536 to 0d69f5d Compare September 19, 2026 06:17
@kong
kong Bot force-pushed the chore/sync-openapi branch from 0d69f5d to b463e46 Compare October 5, 2026 22:54
@kong
kong Bot force-pushed the chore/sync-openapi branch 2 times, most recently from be161cb to d30c70a Compare October 6, 2026 20:37
@kong
kong Bot force-pushed the chore/sync-openapi branch from d30c70a to 5854336 Compare October 7, 2026 02:14

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant