Skip to content
SkillPouch Docs
Search
Ctrl
K
Cancel
Website
SkillPouch on GitHub
Discord
Menu
Getting started
Install
First run
Choosing a pouch and assistants
A second computer
Assistants
Supported assistants
CLI
Configuration
Background sync
Updates
Commands
skillpouch
skillpouch login
skillpouch logout
skillpouch status
skillpouch sync
skillpouch conflicts
skillpouch select
skillpouch unlink
skillpouch daemon
Web app
Pouches and items
Conflicts
Devices
Troubleshooting
Error codes
Security
Security
Self-hosting
Self-hosting overview
Install behind Cloudflare Tunnel
Install on a VPS
Configuration
Sign-in and GitHub
Billing with Polar
File storage
Deploys and day-to-day
Backups
Standby and failover
Moving to a new server
Development
Development setup
Architecture
Performance
Code map
API reference
Overview
health
/healthz
/readyz
session
Overview
Current DPoP nonce
Bind this web session to the browser key that signed the DPoP proof
cli-auth
Overview
CLI starts login (DPoP proof signed by sign_pub required)
Authorize page loads the request (device, keys, location)
CLI cancels its pending request
Authorize: roster add + sealed welcome + key envelopes; creates the device
/v1/cli-auth/requests/{id}/deny
CLI redeems the approved request (PKCE verifier + same DPoP key); long-polls up to `wait` s
Connect a computer: one-time token for `skillpouch login <token>`
Whether a CLI has used the token yet (polling fallback for the event)
Invalidate an unused connect token
devices
Overview
Latest CLI version (from npm) and minimum supported version
Refresh the access token (rotating refresh secret + DPoP proof)
All CLIs and browsers of the account
Rename a CLI (the web: any device; a CLI: itself)
CLI reports its version and detected assistants
Revoke a CLI: effective on its next request; optional signed remove + key rotation
A CLI logs itself out: revoked now and removed from the devices list
Revoke a browser member (ends its sessions)
Report the acknowledged event seq of a pouch
Report the active pouch (display only)
/v1/devices/me/cursors
account
Overview
Current user, account, entitlements and usage
Security events for the Security page
/v1/security/events/{id}/ack
Client-reported E2EE verification failure (should never happen; pages the operator)
Delete the account after a 7-day grace period
Cancel a scheduled account deletion
Lost every unlock method: wipe all encrypted data after 7 days
Cancel a scheduled encrypted-data reset
Account genesis: roster #0 + first pouch + key envelopes (web onboarding only)
Read signed roster statements after a sequence number
Append signed roster statements (+ key envelopes) — add browser/recovery, remove, rotate keys, rename/archive pouch
All roster members (public keys, state)
Key envelopes sealed to the calling member (all pouches, all generations)
Storage used per pouch and per item (sizes only; names stay encrypted)
unlock
Overview
KDF parameters, secret-derived members and passkeys for the unlock screen
Fresh KDF salt + pepper (pending until genesis or a password change commits them)
Release the unlock pepper (10/hour, 30/day per account; audited)
Report a wrong master password (5 in a row notify the other devices)
Key envelopes of a password/passkey/recovery member, for a browser that is unlocking
Change the master password: commit prepared params with add(new) + remove(old)
Trust this browser: add it to the roster, signed by the member that unlocked it
Re-trust this browser after its trust window lapsed (proof signed by a secret member)
/v1/account/security-settings
Trusted-browser window (7–90 days) and auto-lock minutes
WebAuthn registration options for a PRF unlock passkey
Register a passkey unlocker + its signed add(passkey member) statement
Remove a passkey unlocker: signed remove + rotate_keys
Rename a passkey unlocker
WebAuthn assertion options (allowCredentials) for PRF unlock
Verify a passkey assertion; grants this session the passkey member’s envelopes
pouches
List the account’s pouches (including deleted ones still in their undo window)
Create a pouch: signed create_pouch statement + key envelopes for every member
/v1/pouches/{pouchId}
Delete a pouch (7-day undo window, then purged; `skip_undo=true` purges now to free space, also for a pouch already deleted). The last pouch cannot be deleted
Rename or archive a pouch with a signed statement
Make a locked pouch active; at the plan limit `lock_pouch_id` names the active pouch to lock instead
Undo a pouch deletion within the undo window
Remove older versions now: all history + trash of the pouch, or of the listed deleted items
sync
Overview
Which blobs are missing; reserves quota for them
Download one sealed blob (application/octet-stream)
Upload one sealed blob (raw body, Skillpouch-Ciphertext-Hash header)
Upload many small blobs in one request (framed body: id ‖ hash ‖ u32 len ‖ bytes)
Download many blobs in one framed response (id ‖ u32 len ‖ bytes)
Commit 1–50 signed, encrypted operations (optimistic concurrency on revision ids)
Events after a cursor; `wait` (≤ 25 s) long-polls when there are none
Account-wide Server-Sent Events: pouch events + account events (roster, revoke, …)
Start a snapshot (bootstrap or rebase)
One page of artifact heads (tombstones included)
Store this member’s signed (seq, roster head) checkpoint (anti-fork)
/v1/pouches/{pouchId}/checkpoints
artifacts
Live artifacts with their head revision (cursor pagination)
Revision history of one artifact, newest first
Batch-fetch revisions (envelopes + signatures) by id
/v1/pouches/{pouchId}/conflicts
/v1/pouches/{pouchId}/conflicts/{conflictId}
Encrypted binding mirror (where each artifact is installed)
Upsert (or delete with payload=null) this device’s encrypted bindings
billing
Overview
Public, active plans (pricing page)
This account’s subscriptions (newest first) and whether billing is available
Start a hosted checkout for a paid plan
Switch the current subscription to another paid plan (upgrades charge the prorated difference now)
Recent charges of this account (newest first)
Link to the invoice PDF of one of this account’s charges (generated on first request)
Link to the receipt PDF of one of this account’s charges
Pull this account’s subscriptions from the billing provider (for late webhooks)
Customer portal link (manage / cancel)
Polar webhooks (Standard Webhooks signature, idempotent by event id)
admin
Overview
Headline numbers
Earnings, growth, devices, token usage and storage over the last N days
Charges from the billing provider, newest first
Pull charges from the billing provider now
Search users (email, name, id)
User detail: plan, usage, devices, pouches (ids + sizes only), events
/v1/admin/users/{id}/role
Block API access (data is kept)
/v1/admin/users/{id}/unsuspend
/v1/admin/users/{id}/revoke-devices
Give a plan without payment (until a date or forever)
/v1/admin/grants/{id}/revoke
Per-user pouch/storage overrides (e.g. friends, beta testers)
/v1/admin/users/{id}/override
Schedule account deletion (7-day delay)
/v1/admin/plans
Create a plan (paid plans get a provider product)
Edit a plan; limit changes apply to all its users
/v1/admin/subscriptions
/v1/admin/audit
/v1/admin/system
Hold all writes (DB switchover)
import
Overview
Scan a public GitHub repo for skills, plugins, marketplaces, instructions and MCP manifests
marketplaces
Overview
Built-in and added marketplaces, and the GitHub connection
Add a GitHub repository as a marketplace (public, or private via the GitHub App)
Remove an added marketplace
Search or list what a marketplace offers
One item's files, ready to encrypt and save
What one GitHub repository holds, without adding it as a marketplace
One item's files from a GitHub repository, ready to encrypt and save
Repositories the connected GitHub App installations can read
Connect GitHub with the code from its redirect
Disconnect GitHub and remove private-repository marketplaces
usage
Overview
Report the tokens this computer’s assistants used, per UTC day
Tokens used by the account’s assistants, summed over its computers
shares
Create a share link for one item (sealed in the browser)
Every share link of the account, newest first
Revoke a share link; its ciphertext is deleted
Public: whether a link still works, its size and expiry
Public: sealed bundle of a reusable link (application/octet-stream)
Take the bundle of a one-time link; the link is used up
Count an import of a reusable link
Website
SkillPouch on GitHub
Discord
operation_id_reused
Operation ID reused with a different body.
HTTP status
Retryable
409
no
See all
error codes
.