A valid request URL is required to generate request examples{
"requestKey": "save.20260930.001",
"operationId": "createAppLibraryJob",
"state": "completed",
"resourceType": "job",
"resourceId": "job_01",
"resourcePath": "/v1/app-library/jobs/job_01",
"originalStatus": 202,
"createdAt": "2026-09-30T18:00:00Z",
"updatedAt": "2026-09-30T18:00:00Z",
"retainedUntil": "2026-10-07T18:00:00Z",
"error": null
}{
"error": {
"code": "invalid_argument",
"message": "The request could not be accepted. See the error code for the next step.",
"requestId": "req_01",
"field": null,
"retry": "none",
"retryAfterSeconds": null
}
}{
"error": {
"code": "unauthenticated",
"message": "Authenticate before continuing.",
"requestId": "req_01",
"field": null,
"retry": "none",
"retryAfterSeconds": null
}
}{
"error": {
"code": "permission_denied",
"message": "You do not have permission for this action.",
"requestId": "req_01",
"field": null,
"retry": "none",
"retryAfterSeconds": null
}
}{
"error": {
"code": "not_found",
"message": "Resource not found.",
"requestId": "req_01",
"field": null,
"retry": "none",
"retryAfterSeconds": null
}
}{
"error": {
"code": "idempotency_conflict",
"message": "The request could not be accepted. See the error code for the next step.",
"requestId": "req_01",
"field": null,
"retry": "none",
"retryAfterSeconds": null
}
}{
"error": {
"code": "rate_limited",
"message": "The request could not be accepted. See the error code for the next step.",
"requestId": "req_01",
"field": null,
"retry": "same_key_after_delay",
"retryAfterSeconds": 3
}
}{
"error": {
"code": "service_unavailable",
"message": "The request could not be confirmed. Check the original request before continuing.",
"requestId": "req_01",
"field": null,
"retry": "same_key_after_delay",
"retryAfterSeconds": 3
}
}Recover a lost mutation response by original key
Original org/principal and original operation scopes revalidated (not just apps:read). Never returns another actor request even within org. Found request points to original stable resource. 404 is not proof that an action never happened: key may be absent, hidden or expired. Never create a replacement intent on uncertainty.
A valid request URL is required to generate request examples{
"requestKey": "save.20260930.001",
"operationId": "createAppLibraryJob",
"state": "completed",
"resourceType": "job",
"resourceId": "job_01",
"resourcePath": "/v1/app-library/jobs/job_01",
"originalStatus": 202,
"createdAt": "2026-09-30T18:00:00Z",
"updatedAt": "2026-09-30T18:00:00Z",
"retainedUntil": "2026-10-07T18:00:00Z",
"error": null
}{
"error": {
"code": "invalid_argument",
"message": "The request could not be accepted. See the error code for the next step.",
"requestId": "req_01",
"field": null,
"retry": "none",
"retryAfterSeconds": null
}
}{
"error": {
"code": "unauthenticated",
"message": "Authenticate before continuing.",
"requestId": "req_01",
"field": null,
"retry": "none",
"retryAfterSeconds": null
}
}{
"error": {
"code": "permission_denied",
"message": "You do not have permission for this action.",
"requestId": "req_01",
"field": null,
"retry": "none",
"retryAfterSeconds": null
}
}{
"error": {
"code": "not_found",
"message": "Resource not found.",
"requestId": "req_01",
"field": null,
"retry": "none",
"retryAfterSeconds": null
}
}{
"error": {
"code": "idempotency_conflict",
"message": "The request could not be accepted. See the error code for the next step.",
"requestId": "req_01",
"field": null,
"retry": "none",
"retryAfterSeconds": null
}
}{
"error": {
"code": "rate_limited",
"message": "The request could not be accepted. See the error code for the next step.",
"requestId": "req_01",
"field": null,
"retry": "same_key_after_delay",
"retryAfterSeconds": 3
}
}{
"error": {
"code": "service_unavailable",
"message": "The request could not be confirmed. Check the original request before continuing.",
"requestId": "req_01",
"field": null,
"retry": "same_key_after_delay",
"retryAfterSeconds": 3
}
}Authorizations
The control surface credential. Send Authorization: Bearer <token>.
Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.
Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.
Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.
Path Parameters
Caller-generated unique intent key, retained by client before sending. New library restriction, not a change to the legacy visible-ASCII key contract.
1 - 128^(?!\.{1,2}$)[A-Za-z0-9._:-]+$"save.20260930.001"
Response
Successful response.
Read-only lookup under original org and principal, with original operation permissions rechecked. processing describes the HTTP mutation record, not the device job. completed means response durably recorded, not business success. Original job/resource remains authoritative.
Caller-generated unique intent key, retained by client before sending. New library restriction, not a change to the legacy visible-ASCII key contract.
1 - 128^(?!\.{1,2}$)[A-Za-z0-9._:-]+$"save.20260930.001"
processing, completed, not_completed app, version, upload, deletion, inventory_refresh, preview, job ^[A-Za-z0-9][A-Za-z0-9_-]{0,127}$"app_01"
^/v1/app-library/200 <= x <= 599"2026-09-30T18:00:00Z"
"2026-09-30T18:00:00Z"
"2026-09-30T18:00:00Z"
Stable PhoneBase business/request error. No provider payloads, signed URLs, stack traces or internal action keys. HTTP error is distinct from a persisted job result.
Show child attributes
Show child attributes