A valid request URL is required to generate request examples{
"capability": "managed-app-store-v1",
"items": [
{
"appId": "<string>",
"buildId": "<string>",
"name": "<string>",
"category": "<string>",
"packageName": "<string>",
"versionName": "<string>",
"summary": "<string>",
"icon": "<string>",
"installable": true
}
],
"installationAvailable": true
}{
"error": {
"code": "preview_changed",
"message": "A selected device has changed. Review the devices again.",
"requestId": "req_01",
"field": null,
"retry": "new_preview",
"retryAfterSeconds": null
}
}{
"error": {
"code": "preview_changed",
"message": "A selected device has changed. Review the devices again.",
"requestId": "req_01",
"field": null,
"retry": "new_preview",
"retryAfterSeconds": null
}
}{
"error": {
"code": "preview_changed",
"message": "A selected device has changed. Review the devices again.",
"requestId": "req_01",
"field": null,
"retry": "new_preview",
"retryAfterSeconds": null
}
}{
"error": {
"code": "preview_changed",
"message": "A selected device has changed. Review the devices again.",
"requestId": "req_01",
"field": null,
"retry": "new_preview",
"retryAfterSeconds": null
}
}{
"error": {
"code": "preview_changed",
"message": "A selected device has changed. Review the devices again.",
"requestId": "req_01",
"field": null,
"retry": "new_preview",
"retryAfterSeconds": null
}
}{
"error": {
"code": "preview_changed",
"message": "A selected device has changed. Review the devices again.",
"requestId": "req_01",
"field": null,
"retry": "new_preview",
"retryAfterSeconds": null
}
}{
"error": {
"code": "preview_changed",
"message": "A selected device has changed. Review the devices again.",
"requestId": "req_01",
"field": null,
"retry": "new_preview",
"retryAfterSeconds": null
}
}{
"error": {
"code": "preview_changed",
"message": "A selected device has changed. Review the devices again.",
"requestId": "req_01",
"field": null,
"retry": "new_preview",
"retryAfterSeconds": null
}
}List installable apps
Managed Android app store. Requires apps:read, devices:read. Catalogue sources stay on the server. Accepted installs persist before the worker uses native action governance, leases and receipts. After uncertain dispatch only original-receipt and fresh inventory reads run; no automatic reinstall. Installed requires verified exact phone, primary profile, package and catalogue version. All history is tenant/device scoped; activeItems repeats every held installation on each bounded page.
A valid request URL is required to generate request examples{
"capability": "managed-app-store-v1",
"items": [
{
"appId": "<string>",
"buildId": "<string>",
"name": "<string>",
"category": "<string>",
"packageName": "<string>",
"versionName": "<string>",
"summary": "<string>",
"icon": "<string>",
"installable": true
}
],
"installationAvailable": true
}{
"error": {
"code": "preview_changed",
"message": "A selected device has changed. Review the devices again.",
"requestId": "req_01",
"field": null,
"retry": "new_preview",
"retryAfterSeconds": null
}
}{
"error": {
"code": "preview_changed",
"message": "A selected device has changed. Review the devices again.",
"requestId": "req_01",
"field": null,
"retry": "new_preview",
"retryAfterSeconds": null
}
}{
"error": {
"code": "preview_changed",
"message": "A selected device has changed. Review the devices again.",
"requestId": "req_01",
"field": null,
"retry": "new_preview",
"retryAfterSeconds": null
}
}{
"error": {
"code": "preview_changed",
"message": "A selected device has changed. Review the devices again.",
"requestId": "req_01",
"field": null,
"retry": "new_preview",
"retryAfterSeconds": null
}
}{
"error": {
"code": "preview_changed",
"message": "A selected device has changed. Review the devices again.",
"requestId": "req_01",
"field": null,
"retry": "new_preview",
"retryAfterSeconds": null
}
}{
"error": {
"code": "preview_changed",
"message": "A selected device has changed. Review the devices again.",
"requestId": "req_01",
"field": null,
"retry": "new_preview",
"retryAfterSeconds": null
}
}{
"error": {
"code": "preview_changed",
"message": "A selected device has changed. Review the devices again.",
"requestId": "req_01",
"field": null,
"retry": "new_preview",
"retryAfterSeconds": null
}
}{
"error": {
"code": "preview_changed",
"message": "A selected device has changed. Review the devices again.",
"requestId": "req_01",
"field": null,
"retry": "new_preview",
"retryAfterSeconds": null
}
}Authorizations
The control surface credential. Send Authorization: Bearer <token>.
Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.
Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.
Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.