Skip to content

chore(api): sync OpenAPI contract - #5

Draft
kong[bot] wants to merge 1 commit into
mainfrom
chore/sync-openapi
Draft

kong[bot] wants to merge 1 commit into
mainfrom
chore/sync-openapi

Conversation

@kong

@kong kong Bot commented Aug 30, 2026 •

Copy link
Copy Markdown

Summary

API change report

Public API

New Endpoints: 37


POST /mcp
GET /openapi.json
HEAD /openapi.json
GET /openapi.yaml
HEAD /openapi.yaml
GET /projects/{id}/access-tokens
POST /projects/{id}/access-tokens
GET /projects/{id}/access-tokens/usage
DELETE /projects/{id}/access-tokens/{tokenId}
GET /projects/{id}/access-tokens/{tokenId}
GET /projects/{id}/access-tokens/{tokenId}/usage
GET /projects/{id}/durable-functions/{functionId}/executions/{executionId}/operations
PUT /projects/{id}/frontend-shared-variables
GET /projects/{id}/frontends/{frontendId}/function-routes
POST /projects/{id}/frontends/{frontendId}/function-routes
DELETE /projects/{id}/frontends/{frontendId}/function-routes/{routeId}
PUT /projects/{id}/frontends/{frontendId}/function-routes/{routeId}
POST /projects/{id}/sandbox-executions
GET /projects/{id}/sandbox-sessions
POST /projects/{id}/sandbox-sessions
GET /projects/{id}/sandboxes
POST /projects/{id}/sandboxes
DELETE /projects/{id}/sandboxes/{sandboxId}
GET /projects/{id}/sandboxes/{sandboxId}
PATCH /projects/{id}/sandboxes/{sandboxId}
GET /projects/{id}/sandboxes/{sandboxId}/deployments
DELETE /sandbox-sessions/{sessionId}
GET /sandbox-sessions/{sessionId}
POST /sandbox-sessions/{sessionId}/access
POST /sandbox-sessions/{sessionId}/exec
POST /sandbox-sessions/{sessionId}/files/read
POST /sandbox-sessions/{sessionId}/files/write
DELETE /sandbox-sessions/{sessionId}/grants/{subjectId}
PUT /sandbox-sessions/{sessionId}/grants/{subjectId}
POST /sandbox-sessions/{sessionId}/resume
POST /sandbox-sessions/{sessionId}/suspend
GET /sandboxes/presets

Deleted Endpoints: None


Modified Endpoints: 164


POST /auth/signin

  • Description changed from 'Authenticate with email and password. Requires an anon key.

Set session_mode to cookie to request HttpOnly refresh-token
storage. Cookie mode is honored only for an exact, credentialed CORS
origin on the same schemeful site as this API. Otherwise the response
retains the refresh token in its body.
' to 'Authenticate with email and password. Requires an anon key.

Set session_mode to cookie to request HttpOnly refresh-token
storage. Cookie mode is honored only for an exact, credentialed CORS
origin on the same schemeful site as this API. Otherwise the response
retains the refresh token in its body. A frontend on its default
Volcano URL is cross-site with this API and so always gets the body
token.
'

GET /databases/regions

  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Items changed
              • Properties changed
                • Modified property: id
                  • Example changed from 'aws-us-east-1' to 'us-east-1'

POST /databases/{databaseName}/branches/{branchName}/query/delete

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

POST /databases/{databaseName}/branches/{branchName}/query/insert

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

POST /databases/{databaseName}/branches/{branchName}/query/ping

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

POST /databases/{databaseName}/branches/{branchName}/query/select

  • Description changed from 'Query your database using a simple REST API - no SQL required!

Authentication: Requires auth user access token (from signup/signin)

Row-Level Security: Automatically enforced - you see only data you have access to

Use Cases:

  • Query from browser/mobile apps
  • Simple data retrieval
  • Filtered searches with sorting and pagination

Note: For complex queries (JOINs, CTEs), use Lambda functions with direct SQL

Branch-targeted. Runs against the named branch instead of the parent
database, using the branch's own credentials. The branch must be active
and unexpired. Nothing about this request can reach the parent's data.
' to 'Query your database using a simple REST API - no SQL required!

Authentication: Requires auth user access token (from signup/signin)

Row-Level Security: Automatically enforced - you see only data you have access to

Use Cases:

  • Query from browser/mobile apps
  • Simple data retrieval
  • Filtered searches with sorting and pagination

Note: For complex queries (JOINs, CTEs), use a function with direct SQL

Branch-targeted. Runs against the named branch instead of the parent
database, using the branch's own credentials. The branch must be active
and unexpired. Nothing about this request can reach the parent's data.
'

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

POST /databases/{databaseName}/branches/{branchName}/query/update

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

POST /databases/{databaseName}/query/delete

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

POST /databases/{databaseName}/query/insert

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

POST /databases/{databaseName}/query/ping

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

POST /databases/{databaseName}/query/select

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

POST /databases/{databaseName}/query/update

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

GET /deployments

  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • Modified property: data
                • Items changed
                  • Properties changed
                    • Deleted property: artifact_version

POST /durable-functions/{functionId}/executions

  • Responses changed
    • Modified response: 202
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • Modified property: status
                • Description changed from 'Lifecycle state of an execution. pending covers the window between the
                  platform reserving the execution name and the function accepting the
                  start, and has no counterpart once the execution is under way.
                  succeeded, failed, timed_out, stopped and unknown are
                  terminal.

unknown means the platform lost track of the execution's outcome: it
was never seen to finish and is no longer reported, so no result or
error can be given for it. It is terminal because nothing can settle it
later, and it is rare — treat it as an outcome to retry under a new
name rather than a state to wait on. completed_at on an unknown
execution is when the platform gave up, not when the work ended.
' to 'Lifecycle state of an execution. pending covers the window between the
platform reserving the execution name and the function accepting the
start, and has no counterpart once the execution is under way.
succeeded, failed, timed_out, stopped and unknown are
terminal.

unknown means the execution's outcome cannot be established, so no
result or error can be given for it. Either it was under way and was
never seen to finish, or its start failed with a 500 without the
platform establishing whether the execution began — which is why a
name whose start returned an error can later read as unknown rather
than not being found. It is terminal because nothing can settle it
later, and it is rare — treat it as an outcome to retry rather than a
state to wait on. A retry under the same name picks this execution back
up instead of starting a second one, and needs a free concurrency slot
because an unknown execution has given its own up. completed_at on
an unknown execution is when the platform gave up, not when the work
ended.
'

  • Modified response: 503
    • Description changed from 'Durable execution is not available in this environment, or the
      usage limit service could not be reached to charge the start. The
      first is returned by a deployment that has no durable execution
      engine, such as a local one, and is not retryable there; the second
      is transient.
      ' to 'Durable execution is not available in this environment, or the
      plan terms for the start could not be read. The first means the
      capability is paused or this deployment cannot serve it, so it is
      not one to retry in a loop; the second is transient.
      '

GET /functions/resolve

  • Description changed from 'Resolves a DNS-safe function name to its function ID within the caller's project.

SDKs use this endpoint internally to invoke by function name while routing by function ID.

With Service Key:

  • Allowed

With Auth User Token:

  • Allowed

With Anon Key:

  • Requires anon key permission: functions.invoke
  • Function must have is_public: true
    ' to 'Resolves a DNS-safe function name to its function ID and invocation URL within the caller's project.

SDKs use this endpoint internally to invoke by function name while routing by function ID.
Invoke the returned invoke_url as-is. It does not share a domain with the API, so a host
built from the API URL will not reach the function. When the deployment serves no public
invocation domain, as in local development, invoke_url is omitted and callers invoke
through POST /functions/{functionId}/invoke.

With Service Key:

  • Allowed

With Auth User Token:

  • Allowed

With Anon Key:

  • Requires anon key permission: functions.invoke
  • Function must have is_public: true
    '
  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • New property: invoke_url

GET /functions/runtimes

  • Description changed from 'Returns the public function runtime catalog used by CLI clients to select supported runtimes,
    language defaults, and local source packaging metadata for deployments.
    This is a public endpoint that doesn't require authentication.
    ' to 'Returns the public function runtime catalog: every runtime a deploy accepts, its display
    label for runtime pickers, language defaults, durable capability, and local source packaging
    metadata for deployments.
    This is a public endpoint that doesn't require authentication.
    '
  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • Modified property: runtimes
                • Items changed
                  • Required changed
                    • New required property: label
                  • Properties changed
                    • New property: label

POST /functions/{functionId}/invoke

  • Description changed from 'Invoke a serverless function.

With Service Key (admin/background operations):

  • Use for background jobs, webhooks, cron, admin operations
  • Function receives payload only (no user context)
  • Database queries bypass RLS (admin access)

With Auth User Token (user-facing):

  • Use for user-initiated actions
  • Function receives payload + __volcano_auth context:
    {
      user_id: "uuid",
      email: "user@example.com",
      project_id: "uuid",
      role: "authenticated" or "anonymous"
    }
  • Database queries enforce RLS (user-scoped data)

With Anon Key (public function only):

  • Requires anon key permission: functions.invoke
  • Function must have is_public: true
  • Function receives payload only (no __volcano_auth)

Transport and CORS:

  • This operation is the authenticated direct RPC endpoint and always uses the
    POST {payload: ...} contract, including for functions whose DNS ingress is
    configured in HTTP mode.
  • The geo-routed DNS ingress is https://{functionId}.functions.<domain>/.
  • RPC-mode DNS ingress accepts POST at /. HTTP-mode DNS ingress accepts GET,
    HEAD, POST, PUT, PATCH, and DELETE at / and nested paths.
  • Direct and RPC-mode CORS preflight advertises POST, OPTIONS. HTTP-mode DNS
    preflight advertises GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS.
  • http_auth_mode: none applies only to public HTTP-mode DNS ingress; this
    direct operation always requires a Volcano credential.

Durable functions are not invocable here. A durable function's id
answers 404, whatever its visibility, because a synchronous call would
run it with no execution record, no idempotency and no concurrency
accounting. Start one with
POST /durable-functions/{functionId}/executions.
' to 'Invoke a function.

With Service Key (admin/background operations):

  • Use for background jobs, webhooks, cron, admin operations
  • Function receives payload only (no user context)
  • Database queries bypass RLS (admin access)

With Auth User Token (user-facing):

  • Use for user-initiated actions
  • Function receives payload + __volcano_auth context:
    {
      user_id: "uuid",
      email: "user@example.com",
      project_id: "uuid",
      role: "authenticated" or "anonymous"
    }
  • Database queries enforce RLS (user-scoped data)

With Anon Key (public function only):

  • Requires anon key permission: functions.invoke
  • Function must have is_public: true
  • Function receives payload only (no __volcano_auth)

Transport and CORS:

  • This operation is the authenticated direct RPC endpoint and always uses the
    POST {payload: ...} contract, including for functions whose DNS ingress is
    configured in HTTP mode.
  • The geo-routed DNS ingress is the function's invoke_url. It is on a
    different domain from this API, so it cannot be derived from the API host.
  • RPC-mode DNS ingress accepts POST at /. HTTP-mode DNS ingress accepts GET,
    HEAD, POST, PUT, PATCH, and DELETE at / and nested paths.
  • Direct and RPC-mode CORS preflight advertises POST, OPTIONS. HTTP-mode DNS
    preflight advertises GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS.
  • http_auth_mode: none applies only to public HTTP-mode DNS ingress; this
    direct operation always requires a Volcano credential.

Durable functions are not invocable here. A durable function's id
answers 404, whatever its visibility, because a synchronous call would
run it with no execution record, no idempotency and no concurrency
accounting. Start one with
POST /durable-functions/{functionId}/executions.
'

  • Responses changed
    • Modified response: 200
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms
    • Modified response: default
      • Headers changed
        • New header: x-volcano-compute-ms
        • New header: x-volcano-proxy-handler-ms
        • New header: x-volcano-proxy-ms

GET /projects

  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • Modified property: data
                • Items changed
                  • Properties changed
                    • New property: template_installation
                    • Deleted property: aws_application_name
                    • Modified property: plan
                    • Description changed from 'Public plan name; FREE and PRO are accepted from older Hosting responses.' to 'Plan name applied to the project when available.'
                    • Deleted enum values: [FREE PRO]

POST /projects

  • Request body changed
    • Content changed
      • Modified media type: application/json
        • Schema changed
          • Properties changed
            • New property: initialPrompt
            • New property: template_id
  • Responses changed
    • New response: 503
    • Modified response: 201
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • New property: template_installation
              • Deleted property: aws_application_name
              • Modified property: plan
                • Description changed from 'Public plan name; FREE and PRO are accepted from older Hosting responses.' to 'Plan name applied to the project when available.'
                • Deleted enum values: [FREE PRO]

DELETE /projects/{id}

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}

  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • New property: template_installation
              • Deleted property: aws_application_name
              • Modified property: plan
                • Description changed from 'Public plan name; FREE and PRO are accepted from older Hosting responses.' to 'Plan name applied to the project when available.'
                • Deleted enum values: [FREE PRO]
  • Security changed
    • New security requirements: ProjectAccessToken

PATCH /projects/{id}

  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • New property: template_installation
              • Deleted property: aws_application_name
              • Modified property: plan
                • Description changed from 'Public plan name; FREE and PRO are accepted from older Hosting responses.' to 'Plan name applied to the project when available.'
                • Deleted enum values: [FREE PRO]
    • Modified response: 403
      • Description changed from 'Forbidden (for example, selecting subset regions on non-SUPERAGENT plan)' to 'Forbidden (for example, selecting subset regions on plan other than SUPERAGENT)'
  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/anon-keys

  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/anon-keys

  • Security changed
    • New security requirements: ProjectAccessToken

DELETE /projects/{id}/anon-keys/{keyId}

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/anon-keys/{keyId}

  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/anon-keys/{keyId}/regenerate

  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/anon-keys/{keyId}/set-default

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/auth/config

  • Security changed
    • New security requirements: ProjectAccessToken

PUT /projects/{id}/auth/config

  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/auth/config/test-email

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/auth/hosted-pages/{pageType}

  • Security changed
    • New security requirements: ProjectAccessToken

PUT /projects/{id}/auth/hosted-pages/{pageType}

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/auth/insights

  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • Modified property: series
                • Items changed
                  • Properties changed
                    • Modified property: signups
                    • Description changed from 'Accounts created during the bucket.' to 'Accounts created during the bucket that still exist.'
  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/auth/methods

  • Security changed
    • New security requirements: ProjectAccessToken

PUT /projects/{id}/auth/methods

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/auth/pages/appearance

  • Security changed
    • New security requirements: ProjectAccessToken

DELETE /projects/{id}/auth/pages/theme

  • Security changed
    • New security requirements: ProjectAccessToken

PUT /projects/{id}/auth/pages/theme

  • Security changed
    • New security requirements: ProjectAccessToken

DELETE /projects/{id}/auth/pages/{pageType}/layout

  • Security changed
    • New security requirements: ProjectAccessToken

PUT /projects/{id}/auth/pages/{pageType}/layout

  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/auth/pages/{pageType}/preview

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/auth/users

  • Security changed
    • New security requirements: ProjectAccessToken

DELETE /projects/{id}/auth/users/{userId}

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/auth/users/{userId}

  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/auth/users/{userId}/ban

  • Security changed
    • New security requirements: ProjectAccessToken

DELETE /projects/{id}/auth/users/{userId}/sessions

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/auth/users/{userId}/sessions

  • Security changed
    • New security requirements: ProjectAccessToken

DELETE /projects/{id}/auth/users/{userId}/sessions/{sessionId}

  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/auth/users/{userId}/unban

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/config

  • Description changed from 'Exports the project's current user-facing configuration as a
    declarative manifest. Returns JSON by default. Request the canonical
    volcano-config.yaml rendering with Accept: application/yaml or
    ?format=yaml; the YAML is returned verbatim as the raw response body
    (Content-Type: application/yaml) and is meant to be saved as-is.
    Variable values and write-only secrets (SMTP password, OAuth client secrets, TLS material)
    are omitted from the export; shared_variables contains names only; the YAML rendering adds a header comment
    describing how to set them via CLI environment interpolation.
    ' to 'Exports the project's current user-facing configuration as a
    declarative manifest. Returns JSON by default. Request the canonical
    volcano-config.yaml rendering with Accept: application/yaml or
    ?format=yaml; the YAML is returned verbatim as the raw response body
    (Content-Type: application/yaml) and is meant to be saved as-is.
    Variable values and write-only secrets (SMTP password, OAuth client secrets, TLS material)
    are omitted from the export; shared_variables and frontend_shared_variables contain names only; the YAML rendering adds a header comment
    describing how to set them via CLI environment interpolation.
    '
  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • New property: frontend_shared_variables
              • Modified property: databases
                • Items changed
                  • Properties changed
                    • Modified property: region
                    • Description changed from 'Deployed region ID (e.g. aws-us-east-1). Asserted, never written.' to 'Deployed region ID (e.g. us-east-1). Asserted, never written; region IDs issued by earlier versions of the API match too.'
              • Modified property: frontends
                • Items changed
                  • Properties changed
                    • New property: function_routes
                    • New property: variable_scope
                    • New property: variables
              • Modified property: functions
                • Items changed
                  • Properties changed
                    • Modified property: variable_scope
                    • Extensions changed
                    • New extension: x-enum-varnames
              • Modified property: variables
                • Items changed
                  • Properties changed
                    • Modified property: name
                    • Description changed from '' to 'Project variable name. Function runtime names such as AWS_REGION are reserved and fail validation; see the environment variables guide for the full list.'
  • Security changed
    • New security requirements: ProjectAccessToken

PUT /projects/{id}/config

  • Request body changed
    • Content changed
      • Modified media type: application/json
        • Schema changed
          • Properties changed
            • New property: frontend_shared_variables
            • Modified property: databases
              • Items changed
                • Properties changed
                  • Modified property: region
                    • Description changed from 'Deployed region ID (e.g. aws-us-east-1). Asserted, never written.' to 'Deployed region ID (e.g. us-east-1). Asserted, never written; region IDs issued by earlier versions of the API match too.'
            • Modified property: frontends
              • Items changed
                • Properties changed
                  • New property: function_routes
                  • New property: variable_scope
                  • New property: variables
            • Modified property: functions
              • Items changed
                • Properties changed
                  • Modified property: variable_scope
                    • Extensions changed
                    • New extension: x-enum-varnames
            • Modified property: variables
              • Items changed
                • Properties changed
                  • Modified property: name
                    • Description changed from '' to 'Project variable name. Function runtime names such as AWS_REGION are reserved and fail validation; see the environment variables guide for the full list.'
  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/databases

  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • Modified property: data
                • Items changed
                  • Properties changed
                    • Modified property: region
                    • Example changed from 'aws-us-east-1' to 'us-east-1'
  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/databases

  • Summary changed from 'Create a new serverless PostgreSQL database' to 'Create a new PostgreSQL database'
  • Description changed from 'Creates a serverless PostgreSQL database in the project.
    Each project can hold 1 database on Hobby and up to 10,000 on Superagent.
    Requests over the plan's cap return 403.
    ' to 'Creates a PostgreSQL database in the project.
    Each project can hold 1 database on HOBBY and up to 10,000 on SUPERAGENT.
    Requests over the plan's cap return 403.
    '
  • Request body changed
    • Content changed
      • Modified media type: application/json
        • Schema changed
          • Properties changed
            • Modified property: region
              • Description changed from 'Region for database hosting. The accepted values are the regions this
                environment runs in, so read them from GET /databases/regions rather
                than hardcoding a list. A region the environment does not offer is
                rejected with 400.
                ' to 'Region for database hosting, such as us-east-1. The accepted values
                are the regions this environment runs in, so read them from
                GET /databases/regions rather than hardcoding a list. A region the
                environment does not offer is rejected with 400. Region IDs issued by
                earlier versions of the API are still accepted.
                '
              • Example changed from 'aws-us-east-1' to 'us-east-1'
  • Responses changed
    • Modified response: 201
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • Modified property: region
                • Example changed from 'aws-us-east-1' to 'us-east-1'
  • Security changed
    • New security requirements: ProjectAccessToken

DELETE /projects/{id}/databases/{databaseName}

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/databases/{databaseName}

  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • Modified property: region
                • Example changed from 'aws-us-east-1' to 'us-east-1'
  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/databases/{databaseName}/backup-schedule

  • Responses changed
    • Modified response: 403
      • Description changed from 'Backups are SUPERAGENT-only and the owner's plan does not include them' to 'Backups require SUPERAGENT'
  • Security changed
    • New security requirements: ProjectAccessToken

PUT /projects/{id}/databases/{databaseName}/backup-schedule

  • Responses changed
    • Modified response: 403
      • Description changed from 'Backups are SUPERAGENT-only and the owner's plan does not include them' to 'Backups require SUPERAGENT'
  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/databases/{databaseName}/backups

  • Responses changed
    • Modified response: 403
      • Description changed from 'Backups are SUPERAGENT-only and the owner's plan does not include them' to 'Backups require SUPERAGENT'
  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/databases/{databaseName}/backups

  • Responses changed
    • Modified response: 403
      • Description changed from 'The database has reached its backup allowance, or the owner's plan
        does not include backups, which are SUPERAGENT-only.
        ' to 'The database has reached its backup allowance, or the owner's plan
        does not include backups, which are available only on SUPERAGENT.
        '
  • Security changed
    • New security requirements: ProjectAccessToken

DELETE /projects/{id}/databases/{databaseName}/backups/{backupName}

  • Responses changed
    • Modified response: 403
      • Description changed from 'Backups are SUPERAGENT-only and the owner's plan does not include them' to 'Backups require SUPERAGENT'
  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/databases/{databaseName}/backups/{backupName}

  • Responses changed
    • Modified response: 403
      • Description changed from 'Backups are SUPERAGENT-only and the owner's plan does not include them' to 'Backups require SUPERAGENT'
  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/databases/{databaseName}/branches

  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/databases/{databaseName}/branches

  • Security changed
    • New security requirements: ProjectAccessToken

DELETE /projects/{id}/databases/{databaseName}/branches/{branchName}

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/databases/{databaseName}/branches/{branchName}

  • Security changed
    • New security requirements: ProjectAccessToken

PATCH /projects/{id}/databases/{databaseName}/branches/{branchName}

  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/databases/{databaseName}/branches/{branchName}/reset

  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/databases/{databaseName}/branches/{branchName}/reset-password

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/databases/{databaseName}/queries

  • Description changed from 'Returns the database's current top queries from pg_stat_statements
    ranked by total execution time.

SUPERAGENT plan required. This endpoint is only available to projects owned
by users on the SUPERAGENT billing plan.
' to 'Returns the database's current top queries from pg_stat_statements
ranked by total execution time. Only data statements (SELECT, INSERT,
UPDATE, DELETE, MERGE) are listed; statements Volcano runs to operate
the database are left out.

SUPERAGENT plan required. This endpoint is only available to projects owned
by users on the SUPERAGENT billing plan.
'

  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • Modified property: data
                • Items changed
                  • Properties changed
                    • Modified property: query
                    • Description changed from 'Normalized and obfuscated representative query text.' to 'Normalized representative query text with literal values replaced by ?.'
                    • Modified property: role
                    • Description changed from 'Database role used for the query.' to 'Postgres role that ran the query, such as anon or authenticated for RLS-enforced connections, service_role, the database owner role for full-access connections, or a role you created. unknown when the role no longer exists.'
  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/databases/{databaseName}/reset-password

  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/databases/{databaseName}/restores

  • Responses changed
    • Modified response: 403
      • Description changed from 'Backups are SUPERAGENT-only and the owner's plan does not include them' to 'Backups require SUPERAGENT'
  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/databases/{databaseName}/restores

  • Responses changed
    • Modified response: 403
      • Description changed from 'The owner's plan does not include backups or point-in-time restore.
        Both are SUPERAGENT-only.
        ' to 'The owner's plan does not include backups or point-in-time restore.
        Both are available only on SUPERAGENT.
        '
  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/databases/{databaseName}/restores/{restoreId}

  • Responses changed
    • Modified response: 403
      • Description changed from 'Backups are SUPERAGENT-only and the owner's plan does not include them' to 'Backups require SUPERAGENT'
  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/databases/{databaseName}/stats

  • Security changed
    • New security requirements: ProjectAccessToken

PATCH /projects/{id}/databases/{databaseName}/type

  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • Modified property: region
                • Example changed from 'aws-us-east-1' to 'us-east-1'
  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/deployments

  • Description changed from 'Lists Function and Frontend deployment attempts across the project,
    ordered most-recent first. Each item includes a normalized resource
    reference so clients can render both resource types without extra
    fetches.
    ' to 'Lists Function and Frontend deployment attempts across the project,
    ordered most-recent first. Each item includes a normalized resource
    reference so clients can render both resource types without extra
    fetches.

Standard and durable function deployments both appear under
resource.type: function, and resource.kind tells them apart. Pass
function_kind to list one kind only; frontends are then excluded.
Combining function_kind with resource_type=frontend is rejected.
'

  • New query param: function_kind
  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • Modified property: data
                • Items changed
                  • Properties changed
                    • Deleted property: artifact_version
    • Modified response: 400
      • Description changed from 'Bad request - invalid identifier' to 'Bad request - invalid identifier or filter, or function_kind combined with resource_type=frontend'
  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/deployments/summary

  • Description changed from 'Summarizes deployment attempts for one comparable resource pipeline.
    Success rate uses conclusive outcomes only: active and deleted attempts
    are successful; failed and degraded attempts are failures; in-progress
    and superseded attempts are excluded. Median build duration includes
    completed, non-superseded attempts with recorded build work,
    including failed builds.
    ' to 'Summarizes deployment attempts for one comparable resource pipeline.
    Success rate uses conclusive outcomes only: active and deleted attempts
    are successful; failed and degraded attempts are failures; in-progress
    and superseded attempts are excluded. Median build duration includes
    completed, non-superseded attempts with recorded build work,
    including failed builds.

With resource_type=function, pass function_kind to summarize one
kind of function only. It is rejected with resource_type=frontend.
'

  • New query param: function_kind
  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • Modified property: median_build_duration_seconds
                • Description changed from 'Median CodeBuild duration across eligible completed attempts.' to 'Median build duration across eligible completed attempts.'
    • Modified response: 400
      • Description changed from 'Bad request - invalid identifier or filter' to 'Bad request - invalid identifier or filter, or function_kind combined with resource_type=frontend'
  • Security changed
    • New security requirements: ProjectAccessToken

GET /projects/{id}/domains

  • Responses changed
    • Modified response: 200
      • Content changed
        • Modified media type: application/json
          • Schema changed
            • Properties changed
              • Modified property: data
                • Items changed
                  • Property 'AllOf' changed
                    • Modified schema: #/components/schemas/FrontendCustomDomainResponse
                    • Properties changed
                    • New property: routing_target_hostname
  • Security changed
    • New security requirements: ProjectAccessToken

POST /projects/{id}/durable-functions

  • Request body changed
    • Content changed
      • Modified media type: multipart/form-data
        • Schema changed
          • Properties changed
            • Modified property: variable_scope
              • Extensions changed
                • New extension: x-enum-varnames

DELETE /projects/{id}/durable-functions/{functionId}

  • Description changed from 'Accepted for asynchronous teardown; the work conti

Report truncated; see the source commit for the complete contract diff.

Validation

@kong
kong Bot force-pushed the chore/sync-openapi branch 6 times, most recently from c6391e8 to ea3d391 Compare September 5, 2026 02:49
@kong
kong Bot force-pushed the chore/sync-openapi branch 2 times, most recently from 1af2768 to 09b12fe Compare September 10, 2026 22:00
@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@kong
kong Bot force-pushed the chore/sync-openapi branch 13 times, most recently from 574efbb to 3d26a9c Compare September 17, 2026 18:05
@kong
kong Bot force-pushed the chore/sync-openapi branch 8 times, most recently from 4f5a9fd to 3fada80 Compare September 19, 2026 06:17
@kong
kong Bot force-pushed the chore/sync-openapi branch 18 times, most recently from 18f1695 to cb3d502 Compare September 26, 2026 23:34
@kong
kong Bot force-pushed the chore/sync-openapi branch 8 times, most recently from 9778a23 to 2619f2e Compare September 29, 2026 02:12
@kong
kong Bot force-pushed the chore/sync-openapi branch from 2619f2e to d2604fa Compare September 29, 2026 04:04

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant