1.1.0.
Verify the schema
Run the freshness check from the repository root:docs/openapi.json.
Route groups
The schema also includes an experimental observation transport probe and a raw changed-frame action route. Treat the experimental observation contract as Alpha.
Authentication
Health and readiness probes are unauthenticated. Protected control routes use the daemon authentication policy selected at startup. The Python SDK can use a local bearer token, Modal Connect identity, or the SDK-managed tunnel flow. The OpenAPI document does not declare a global security scheme. Do not infer that a control route is unauthenticated from the absence of a schema-level security entry. Keep credentials in headers. Do not put them in URL queries.Request and response behavior
The daemon accepts JSON for most control routes. Artifact PUT requests stream bytes and do not use the JSON body ceiling. Raw screenshot routes return image bytes. Direct errors use{code, message, details}. Validation failures can also use the generated FastAPI validation schema.
Action batches have two timeout levels:
- A per-action timeout
- A whole-batch duration limit
continue_on_error is true. Idempotency-Key can replay a completed batch response without re-executing the actions. Reusing the key with a different body returns HTTP 409.
Version check
Read/v1/version before a client depends on a version-specific contract. Read /v1/capabilities before it depends on an optional backend or runtime capability.

