Skip to content

Requests

Submitting data to a request by slug.

GET /api/public/requests/{slug}

Probe a request

Unauthenticated

Callable with no credential.

Describes what a request is asking for — its template, whether it needs a password, an identifier or a proven identity — plus the requester's identity claim so the responder can verify who is asking before answering.

Parameters

Name In Required Notes
slug path yes The capability. Unguessable by construction and never derived from anything user-visible — whoever holds it holds the access.

Responses

Status Meaning
200 The request's shape and the requester's claim.
404 No such resource, or the caller may not see it.
429 Too many attempts. Password gates, probes and challenges are limited per client, so a slug cannot be brute-forced.

Response fields

Field Type Notes
label string
status string
requiresPassword boolean
requiresIdentifier boolean
requireHandshake boolean
allowExtraFields boolean
identityScope string (any | from_root) Which identities the request will accept.
template array of TemplateItem
requester Sharer
server ServerClaim

POST /api/public/requests/{slug}

Submit a response

Auth: Session

Answers a request. Requires an account on this server: the answer is minted as a revocable link in the responder's own workspace, where they can update or withdraw it. An unauthenticated call is refused with request_account_required. Submitting again from the same account updates the existing response rather than creating a second one.

An identity is recorded only when a challenge signature verified. A claimed identityId without one is dropped, not attributed — otherwise anyone could submit under someone else's name.

If the request names a callback URL, a successful submission is POSTed onward to it.

Parameters

Name In Required Notes
slug path yes The capability. Unguessable by construction and never derived from anything user-visible — whoever holds it holds the access.

Request body

application/json

Field Type Notes
data object Answers keyed by template key.
mappings object Answers supplied as references to the responder's own vault records rather than as literal values, so the requester keeps resolving the current value. Same-server only.
senderName string
identifier string Required when the probe reported requiresIdentifier.
password string
identityId string
handshakeToken string
challengeNonce string
challengeSignature string

Responses

Status Meaning
200 The submission was recorded.
401 Refused, with a named reason.
404 No such resource, or the caller may not see it.
429 Too many attempts. Password gates, probes and challenges are limited per client, so a slug cannot be brute-forced.