Skip to main content
GET
List curated extension packages available to the organization

Authorizations

Authorization
string
header
required

OAuth 2.0 access token obtained through RFC 8628 at /api/auth/device/code and /api/auth/oauth2/token. The API enforces governance:read, session:write, and client-status:write as appropriate.

Response

200 - application/json

Digest-pinned package catalog

id
string
required
Pattern: ^[a-z0-9-]+$
version
string
required
source_ref
string
required

Immutable HTTPS or local .tar.gz archive

sha256
string
required
Pattern: ^[A-Fa-f0-9]{64}$
name
string
artifact_id
string<uuid>

Organization-scoped mirrored artifact

platform_sources
object

Exact <os>-<arch> archive overrides; clients require a matching entry when this map is present.

settings
object
adapters
object