Skip to main content
POST
Error

Authorizations

Authorization
string
header
required

The control surface credential. Send Authorization: Bearer <token>.

Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.

Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.

Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.

Headers

Idempotency-Key
string
required

Original store.v2 identity/app/build/phone/profile binding. Recovery uses GET; a second key is a new request and is refused while the target is held.

Required string length: 1 - 160

Body

application/json

Trusted catalogue build and confirmed primary Android target. Arbitrary URLs, APK bytes, leases and provider parameters are refused.

appId
string
required
Pattern: ^[a-z0-9._-]{1,36}$
buildId
string
required
Pattern: ^[a-z0-9._-]{1,36}$
deviceId
string
required
Required string length: 1 - 160
scopeId
string
required
Allowed value: "user_0"

Response

Durable installation accepted; result is not yet installed.

installation
object
required