2.0.2.
Verify the schema
docs/openapi.json differs from the daemon application.
Main route groups
/v1/steps returns the bounded versioned Computer Step binary envelope. It contains the ordered action result, nested image outputs, the final semantic screenshot, and timing. Clients validate its media type, bounds, segment digests, and screenshot metadata.
Authentication
Health and readiness probes are unauthenticated. Protected routes use the daemon authentication policy selected at startup. Python clients can use a local bearer token, Modal Connect identity, or the SDK-managed attested tunnel. Keep credentials in headers. Never put credentials in URL queries.Mutation rules
- Validate a complete action batch before mutation.
- Serialize input and Step mutations under one lock.
- Do not retry after possible dispatch.
- Use operation receipts to resolve ambiguous responses.
- Treat the immediate Step frame as an observation. Define readiness in the application.
Check compatibility
Read/v1/version and /v1/capabilities before lease acquisition. The protocol and required
capabilities determine compatibility.
Use Namespaces for Python applications. Use the schema for direct HTTP clients and generated tooling.
