API
Registry v1
Development base URL: https://dev.studio247.co/api/v1/registry
Implemented
Authentication uses a Sanctum bearer token. Read scope is registry:read. Write scope is registry:write, which also allows reads. Publish requires a verified email and the labeled development grant. Pagination on publisher lists uses cursor and limit. Errors use error.code, error.message, error.request_id, and optional error.fields. Publish requires an Idempotency-Key header of 8 to 80 characters. The same key and body replay the original release. A different body with the same key returns conflict.
Create, upload, validate, publish
POST https://dev.studio247.co/api/v1/registry/publishers/your-slug/packages
{"slug":"confetti","type":"plugin","visibility":"public","description":"Registry contract sample. Not an Engine plugin."}
POST https://dev.studio247.co/api/v1/registry/packages/your-slug/confetti/drafts
{"manifest":{"schema_version":"1","name":"confetti","version":"1.0.0","type":"plugin","visibility":"public","license":"MIT","description":"Registry contract sample. Not an Engine plugin.","capabilities":{"provides":["registry.sample"]}},"expected_revision":0}
POST https://dev.studio247.co/api/v1/registry/drafts/{draft_id}/artifact
multipart field: artifact
POST https://dev.studio247.co/api/v1/registry/drafts/{draft_id}/validate
POST https://dev.studio247.co/api/v1/registry/drafts/{draft_id}/publish
Idempotency-Key: a unique key
{"expected_revision":2}
Browse, manifest, artifact, resolve
GET https://dev.studio247.co/api/v1/registry/packages?type=plugin
GET https://dev.studio247.co/api/v1/registry/packages/your-slug/confetti
GET https://dev.studio247.co/api/v1/registry/packages/your-slug/confetti/versions/1.0.0/manifest
GET https://dev.studio247.co/api/v1/registry/packages/your-slug/confetti/versions/1.0.0/download
POST https://dev.studio247.co/api/v1/registry/resolve
{"publisher":"your-slug","slug":"confetti","constraint":"1.0.0"}
The site also serves public registry pages without a token. Private packages return not_found to callers who cannot see them. Yank, deprecate, and revoke do not change published manifest or artifact bytes. Signing uses Ed25519 over the canonical attestation JSON. A valid signature is not a safety verdict.
Proposed
Payment checkout, marketplace payouts, and branded app provisioning are not in this API. Engine playback and schedule execution are not implemented.