A valid request URL is required to generate request examples{
"refreshId": "refresh_01",
"state": "processing",
"requestedAt": "2026-09-30T18:00:00Z",
"finishedAt": null,
"targetCount": 1,
"completedCount": 0,
"notCompletedCount": 0,
"nextPollAfterSeconds": 3,
"servicePromise": {
"promisedBy": "2026-09-30T18:10:00Z",
"estimatedCompletionAt": "2026-09-30T18:08:00Z",
"nextUpdateAt": "2026-09-30T18:05:00Z",
"delayed": false
}
}{
"error": {
"code": "invalid_argument",
"message": "The request could not be accepted. See the error code for the next step.",
"requestId": "req_01",
"field": null,
"retry": "none",
"retryAfterSeconds": null
}
}{
"error": {
"code": "unauthenticated",
"message": "Authenticate before continuing.",
"requestId": "req_01",
"field": null,
"retry": "none",
"retryAfterSeconds": null
}
}{
"error": {
"code": "permission_denied",
"message": "You do not have permission for this action.",
"requestId": "req_01",
"field": null,
"retry": "none",
"retryAfterSeconds": null
}
}{
"error": {
"code": "not_found",
"message": "Resource not found.",
"requestId": "req_01",
"field": null,
"retry": "none",
"retryAfterSeconds": null
}
}{
"error": {
"code": "idempotency_conflict",
"message": "The request could not be accepted. See the error code for the next step.",
"requestId": "req_01",
"field": null,
"retry": "none",
"retryAfterSeconds": null
}
}{
"error": {
"code": "preview_changed",
"message": "A selected device has changed. Review the devices again.",
"requestId": "req_01",
"field": null,
"retry": "new_preview",
"retryAfterSeconds": null
}
}{
"error": {
"code": "rate_limited",
"message": "The request could not be accepted. See the error code for the next step.",
"requestId": "req_01",
"field": null,
"retry": "same_key_after_delay",
"retryAfterSeconds": 3
}
}{
"error": {
"code": "service_unavailable",
"message": "The request could not be confirmed. Check the original request before continuing.",
"requestId": "req_01",
"field": null,
"retry": "query_original",
"retryAfterSeconds": 3
}
}Request bounded read-only application checks
All IDs authorized before admission; invisible/cross-org target ->404. Per-target transport/offline failures recorded after acceptance. Coalesce identical concurrent reads and apply refresh policy; do not wake, acquire, renew or run an install as a probe.
A valid request URL is required to generate request examples{
"refreshId": "refresh_01",
"state": "processing",
"requestedAt": "2026-09-30T18:00:00Z",
"finishedAt": null,
"targetCount": 1,
"completedCount": 0,
"notCompletedCount": 0,
"nextPollAfterSeconds": 3,
"servicePromise": {
"promisedBy": "2026-09-30T18:10:00Z",
"estimatedCompletionAt": "2026-09-30T18:08:00Z",
"nextUpdateAt": "2026-09-30T18:05:00Z",
"delayed": false
}
}{
"error": {
"code": "invalid_argument",
"message": "The request could not be accepted. See the error code for the next step.",
"requestId": "req_01",
"field": null,
"retry": "none",
"retryAfterSeconds": null
}
}{
"error": {
"code": "unauthenticated",
"message": "Authenticate before continuing.",
"requestId": "req_01",
"field": null,
"retry": "none",
"retryAfterSeconds": null
}
}{
"error": {
"code": "permission_denied",
"message": "You do not have permission for this action.",
"requestId": "req_01",
"field": null,
"retry": "none",
"retryAfterSeconds": null
}
}{
"error": {
"code": "not_found",
"message": "Resource not found.",
"requestId": "req_01",
"field": null,
"retry": "none",
"retryAfterSeconds": null
}
}{
"error": {
"code": "idempotency_conflict",
"message": "The request could not be accepted. See the error code for the next step.",
"requestId": "req_01",
"field": null,
"retry": "none",
"retryAfterSeconds": null
}
}{
"error": {
"code": "preview_changed",
"message": "A selected device has changed. Review the devices again.",
"requestId": "req_01",
"field": null,
"retry": "new_preview",
"retryAfterSeconds": null
}
}{
"error": {
"code": "rate_limited",
"message": "The request could not be accepted. See the error code for the next step.",
"requestId": "req_01",
"field": null,
"retry": "same_key_after_delay",
"retryAfterSeconds": 3
}
}{
"error": {
"code": "service_unavailable",
"message": "The request could not be confirmed. Check the original request before continuing.",
"requestId": "req_01",
"field": null,
"retry": "query_original",
"retryAfterSeconds": 3
}
}Authorizations
The control surface credential. Send Authorization: Bearer <token>.
Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.
Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.
Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.
Headers
Required for an inventory refresh. The same organization, actor, key and canonical request return the original result. A changed intent conflicts. Query the original /requests/{requestKey} after a lost response; no automatic mutation retry. Caller-generated unique intent key, retained by client before sending. New library restriction, not a change to the legacy visible-ASCII key contract.
1 - 128^(?!\.{1,2}$)[A-Za-z0-9._:-]+$"save.20260930.001"
Body
Explicit finite scope. Omit packageName to collect the full installed-app inventory. Pure read only: never acquire/renew leases, wake/boot devices or run a substitute app action. Unsupported read-only transport returns a per-target reason.
Response
Accepted; follow returned resource.
^[A-Za-z0-9][A-Za-z0-9_-]{0,127}$"app_01"
processing, completed, partially_completed, not_completed "2026-09-30T18:00:00Z"
"2026-09-30T18:00:00Z"
x >= 1x >= 0x >= 0x >= 1Original promisedBy never resets on retry/poll. nextUpdateAt must correspond to a real scheduled update and accountable service; null does not authorize indefinite waiting.
Show child attributes
Show child attributes
{
"promisedBy": "2026-09-30T18:10:00Z",
"estimatedCompletionAt": "2026-09-30T18:08:00Z",
"nextUpdateAt": "2026-09-30T18:05:00Z",
"delayed": false
}