openapi: 3.2.0 info: title: Temp.md Embedded Preview Platform Publish Grants API version: 0.1.0 description: Versioned partner API for creating and governing previews on behalf of opaque end customers. Application keys are server credentials; browser publishers must use short-lived publish grants. servers: - url: https://api.temp.md tags: - name: Publish Grants paths: /v1/publish-grants: post: operationId: createPublishGrant summary: Mint one short-lived delegated browser publish grant description: Application keys are server-only. Return the grant, not the Application key, to a browser or Electron renderer. security: - applicationBearer: [] requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CreatePublishGrant' responses: '201': description: One-time publish grant '400': $ref: '#/components/responses/Error' '401': $ref: '#/components/responses/Error' '403': $ref: '#/components/responses/Error' '404': $ref: '#/components/responses/Error' tags: - Publish Grants /v1/publish-grants/{grantId}: delete: operationId: revokePublishGrant summary: Revoke a delegated publish grant security: - applicationBearer: [] parameters: - name: grantId in: path required: true schema: type: string responses: '200': description: Grant revoked '404': $ref: '#/components/responses/Error' tags: - Publish Grants components: schemas: CreatePublishGrant: type: object required: - operation properties: operation: enum: - create - update previewId: type: string externalSubjectId: type: string maxLength: 200 externalProjectId: type: string maxLength: 200 ttlSeconds: type: integer minimum: 60 maximum: 900 maxFiles: type: integer minimum: 1 maximum: 100 maxFileBytes: type: integer minimum: 1 maximum: 10485760 maxTotalBytes: type: integer minimum: 1 maximum: 52428800 Error: type: object required: - error - code properties: error: type: string code: type: string message: type: string request_id: type: string responses: Error: description: Structured error content: application/json: schema: $ref: '#/components/schemas/Error' securitySchemes: dashboardBearer: type: http scheme: bearer description: A Temp.md dashboard session or personal account API key. applicationBearer: type: http scheme: bearer bearerFormat: tempmd_app__ description: Server-only Application key with explicit scopes. publishGrantBearer: type: http scheme: bearer bearerFormat: tempmd_grant__ description: Short-lived, one-session delegated publishing authority. reviewBearer: type: http scheme: bearer bearerFormat: tempmd_view__ description: Short-lived viewer capability bound to one frozen review request.