Skip to content

Endpoints

This page maps WarmHub’s mounted REST endpoints for repository reads, action observability, component installs, and the MCP and streaming transports. Most rows link to the page that documents the endpoint in detail. A few mounted routes are owned by other pages — see Documented elsewhere below. For base URL, authentication, request and response format, idempotency, and pagination, see the Overview.

Endpoints marked None are publicly accessible for public repositories. Private repositories require a valid Bearer token.

MethodPathDescriptionAuth
GET/api/repos/:org/:repo/headHEAD snapshotNone
GET/api/repos/:org/:repo/about/:wrefAssertions about a thingNone
GET/api/repos/:org/:repo/queryFiltered queryNone
GET/api/repos/:orgName/:repoName/exportExport repo contents as NDJSON; supports synchronous streaming, async job minting (prefer=async), and async job redemption (token=<exportToken>)repo:read (unrestricted) and repo:checkpoint-read; not available to component tokens

GET /api/repos/:orgName/:repoName/export

Exports the contents of a repository. The endpoint has three response modes selected by query parameters:

Synchronous NDJSON stream (default)

Omit both prefer and token. The server streams the export as NDJSON directly in the response body.

Async job minting (prefer=async)

Pass prefer=async. The server mints an export job and returns 202 immediately:

{ "exportToken": "<token>", "atRepoSeq": 42 }

Use the returned exportToken to poll for completion.

Async job redemption (token=<exportToken>)

Pass token=<exportToken> (the value from the minting response). While the job is still building, the server returns 202:

{ "state": "pending" }

Once the job is complete, the server returns 200 application/json with a signed download URL and metadata:

{
"url": "<signed-storage-url>",
"expiresAt": 1718000000000,
"atRepoSeq": 42,
"recordCount": 1234,
"contentSha256": "<hex digest>"
}

expiresAt is a Unix timestamp in milliseconds (a JSON number). Download the NDJSON export directly from the url in the response. The URL expires at expiresAt.

Auth: repo:checkpoint-read plus unrestricted repo:read. A token whose repo:read is narrowed to particular refs or shapes gets a 403 from this endpoint even when repo:checkpoint-read is also present — see Personal access tokens for how scope narrowing works.

Component tokens cannot use this endpoint at all. A component call returns 403 on both the synchronous stream and the async paths whatever scopes the token carries, including repo:checkpoint-read with unrestricted repo:read. A component that needs repository bytes must have a user or PAT-backed caller drive the export.

Query parameters:

ParameterValuesDescription
preferasyncMint an async export job instead of streaming synchronously
token<exportToken>Redeem a previously minted async export job
MethodPathDescriptionAuth
GET/api/repos/:org/:repo/actions/runsList action runsrepo:configure
GET/api/repos/:org/:repo/actions/runs/:runId/attemptsGet run attemptsrepo:configure
GET/api/repos/:org/:repo/actions/notificationsList repo-scoped action notification records for terminal failuresrepo:configure
POST/api/action-runs/:runId/callbackReport async action progress or completionrepo:action-callback (repo-scoped runs); org:action-callback (org-scoped runs)
MethodPathDescriptionAuth
POST/mcpMCP HTTP transport (GET returns 405)Bearer token required for some tools; others are accessible without credentials. See MCP Server for details.
GET/sseServer-sent invalidation stream with a live ticketLive ticket
POST/api/repos/:orgName/:repoName/streams/:streamId/submissionsNDJSON streaming submission routerepo:write

Note: The NDJSON submission route (/streams/:streamId/submissions) is enabled per repository. On a repository where it is not enabled it answers 404 — the same response as an unknown path, so a 404 here does not distinguish “not enabled” from “no such repo”.

The first two routes are the install handshake. cli/:method is the transport behind wh component exec — see the CLI reference for how to invoke component methods.

MethodPathDescriptionAuth
POST/api/component-registry/:orgName/:componentName/resolveResolve the latest manifest and check install eligibilityrepo:write on the install repo
POST/api/component-registry/:orgName/:componentName/setup-callDispatch the optional registered-component setup callbackrepo:write on the install repo
POST/api/component-registry/:orgName/:componentName/cli/:methodDispatch an installed component’s CLI method (via wh component exec)repo:read on the install repo, plus any per-method permission the method declares; owner-org membership is additionally required when the component is private

These surfaces are intentionally documented through SDK, CLI, and MCP workflows rather than REST endpoint references:

SurfaceUse Instead
Shape managementSDK shape APIs, wh shape, or commit writes
Organization and repository managementCLI org/repo commands or SDK org/repo APIs
Repository writesWrites
Subscription managementSubscription CLI/MCP workflows
Credential set managementCredential CLI workflows
PAT managementPersonal Access Tokens guide

A few other mounted routes are documented on the pages that own those surfaces, so they are not repeated here:

RoutesDocumented on
MCP OAuth metadata — /.well-known/oauth-protected-resource, /.well-known/oauth-protected-resource/mcp, /mcp/.well-known/oauth-protected-resource, /.well-known/oauth-authorization-serverMCP Server
Raw repository content — /:org/:repo/readme.md, /:org/:repo/agents.md, /:org/:repo/llms.txtContent shapes