Skip to main content
The daemon publishes an OpenAPI 3.1 contract. The checked-in schema reports package version 2.0.2.

Verify the schema

The command fails when docs/openapi.json differs from the daemon application.

Main route groups

/v1/steps returns the bounded versioned Computer Step binary envelope. It contains the ordered action result, nested image outputs, the final semantic screenshot, and timing. Clients validate its media type, bounds, segment digests, and screenshot metadata.

Authentication

Health and readiness probes are unauthenticated. Protected routes use the daemon authentication policy selected at startup. Python clients can use a local bearer token, Modal Connect identity, or the SDK-managed attested tunnel. Keep credentials in headers. Never put credentials in URL queries.

Mutation rules

  • Validate a complete action batch before mutation.
  • Serialize input and Step mutations under one lock.
  • Do not retry after possible dispatch.
  • Use operation receipts to resolve ambiguous responses.
  • Treat the immediate Step frame as an observation. Define readiness in the application.
JSON and REST routes remain available for direct integrations and compatibility. The optimized SDK path uses one pooled client for the leased trajectory.

Check compatibility

Read /v1/version and /v1/capabilities before lease acquisition. The protocol and required capabilities determine compatibility. Use Namespaces for Python applications. Use the schema for direct HTTP clients and generated tooling.