openapi: 3.2.0 info: title: temp.md Public Accounts API version: 1.0.0 description: Publish agent-made files and applications to one canonical URL, update them atomically, and recover owner credentials without changing the shared link. termsOfService: https://temp.md/terms license: name: API terms url: https://temp.md/terms servers: - url: https://api.temp.md description: Production tags: - name: Accounts paths: /auth/signup: post: operationId: signup summary: Create an account tags: - Accounts requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SignupInput' responses: '201': description: Authenticated account content: application/json: schema: $ref: '#/components/schemas/LoginResult' '400': $ref: '#/components/responses/BadRequest' '409': $ref: '#/components/responses/Conflict' '429': $ref: '#/components/responses/RateLimited' /auth/login: post: operationId: login summary: Create an account session tags: - Accounts requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/LoginInput' responses: '200': description: Authenticated account content: application/json: schema: $ref: '#/components/schemas/LoginResult' '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '429': $ref: '#/components/responses/RateLimited' /me/api-keys: get: operationId: listApiKeys summary: List named API keys without secrets tags: - Accounts security: - accountBearer: [] responses: '200': description: Key metadata content: application/json: schema: type: object required: - keys properties: keys: type: array items: $ref: '#/components/schemas/ApiKey' '401': $ref: '#/components/responses/Unauthorized' post: operationId: createApiKey summary: Create a named API key description: The raw token is returned once and stored only as a hash. tags: - Accounts security: - accountBearer: [] requestBody: required: true content: application/json: schema: type: object required: - name properties: name: type: string minLength: 1 maxLength: 64 additionalProperties: false responses: '201': description: Key and one-time secret content: application/json: schema: type: object required: - key - token - message properties: key: $ref: '#/components/schemas/ApiKey' token: type: string writeOnly: true message: type: string '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '409': $ref: '#/components/responses/Conflict' '429': $ref: '#/components/responses/RateLimited' /me/api-keys/{keyId}: delete: operationId: revokeApiKey summary: Revoke an API key immediately tags: - Accounts security: - accountBearer: [] parameters: - name: keyId in: path required: true schema: type: string pattern: ^[a-f0-9]{32}$ responses: '200': $ref: '#/components/responses/SuccessObject' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' /me/temps/{tempId}/update-token: post: operationId: rotateUpdateToken summary: Recover a lost scoped update token description: Atomically invalidates every prior update token and returns one replacement exactly once. tags: - Accounts security: - accountBearer: [] parameters: - $ref: '#/components/parameters/TempId' responses: '200': description: Replacement credential and Temp state content: application/json: schema: type: object required: - tempId - canonicalUrl - updateToken - status - expiresAt - spaMode - message properties: tempId: type: string canonicalUrl: type: string format: uri updateToken: type: string writeOnly: true status: $ref: '#/components/schemas/LifecycleStatus' expiresAt: type: - string - 'null' format: date-time spaMode: type: boolean message: type: string '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' '429': $ref: '#/components/responses/RateLimited' components: schemas: ApiKey: type: object required: - id - name - suffix - status - createdAt - lastUsedAt - revokedAt - current properties: id: type: string pattern: ^[a-f0-9]{32}$ name: type: string suffix: type: string pattern: ^[a-f0-9]{8}$ status: enum: - active - revoked createdAt: type: string format: date-time lastUsedAt: type: - string - 'null' format: date-time revokedAt: type: - string - 'null' format: date-time current: type: boolean LoginInput: type: object required: - email - password properties: email: type: string format: email maxLength: 254 password: type: string format: password minLength: 1 maxLength: 128 writeOnly: true additionalProperties: false LoginResult: type: object required: - token - userId - email properties: token: type: string writeOnly: true userId: type: string email: type: string format: email SignupInput: allOf: - $ref: '#/components/schemas/LoginInput' - type: object properties: password: type: string format: password minLength: 8 maxLength: 128 writeOnly: true LifecycleStatus: type: string enum: - drafting - active - cooling - expired Error: type: object required: - error properties: error: type: string code: type: string message: type: string request_id: type: string docs_url: type: string format: uri retry_after: type: integer minimum: 0 additionalProperties: true responses: RateLimited: description: Rate limit exceeded headers: Retry-After: schema: type: integer minimum: 0 content: application/json: schema: $ref: '#/components/schemas/Error' SuccessObject: description: Successful response content: application/json: schema: type: object additionalProperties: true BadRequest: description: Invalid request content: application/json: schema: $ref: '#/components/schemas/Error' NotFound: description: Resource not found content: application/json: schema: $ref: '#/components/schemas/Error' Unauthorized: description: Authentication required or invalid content: application/json: schema: $ref: '#/components/schemas/Error' Forbidden: description: Credential lacks access content: application/json: schema: $ref: '#/components/schemas/Error' Conflict: description: Request conflicts with current state content: application/json: schema: $ref: '#/components/schemas/Error' parameters: TempId: name: tempId in: path required: true schema: type: string securitySchemes: tempCapability: type: http scheme: bearer bearerFormat: tempmd scoped capability publishSessionToken: type: http scheme: bearer bearerFormat: tempmd_upload session capability accountBearer: type: http scheme: bearer bearerFormat: JWT or tempmd_key API key externalDocs: description: temp.md documentation url: https://temp.md/docs