> ## Documentation Index
> Fetch the complete documentation index at: https://docs.bluee.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# Resolve, hash, and optionally mirror a managed repository source



## OpenAPI

````yaml /openapi/next.yaml post /admin/package-source/inspect
openapi: 3.1.0
info:
  title: Blue — Service Contract
  version: 0.1.0
  description: >
    The client-side contract the `blue` CLI expects from the provisioned
    service. The reference `control-api` implements it; any BYO service that
    honors these shapes can be swapped in. Gateway-mode inference JWT issuance
    is OPTIONAL — governance-only deployments need only `GET
    /governance-config`. CLI callers use OAuth 2.0 access tokens issued through
    RFC 8628 device authorization; dashboard callers use an HTTP-only Better
    Auth session cookie.
servers:
  - url: https://harness.example.com
    description: Replace with the Control API URL for your deployment.
security:
  - oauthDevice: []
tags:
  - name: System
    description: Service health and authenticated identity.
  - name: Configuration
    description: Personalized governance policy and client reconciliation state.
  - name: Gateway
    description: Per-user managed inference-gateway credential lifecycle.
  - name: Sessions
    description: Raw-session upload, metadata, and download lifecycle.
  - name: Administration
    description: Organization-administrator policy and client operations.
  - name: User management
    description: >-
      Organization user lifecycle, session revocation, and invitation
      operations.
  - name: Identity provisioning
    description: SCIM 2.0 user and group provisioning for an external identity provider.
paths:
  /admin/package-source/inspect:
    post:
      tags:
        - Administration
      summary: Resolve, hash, and optionally mirror a managed repository source
      operationId: inspectManagedPackageSource
      requestBody:
        required: true
        content:
          application/json:
            schema:
              oneOf:
                - type: object
                  required:
                    - source_ref
                  properties:
                    source_ref:
                      type: string
                      description: >-
                        Public GitHub source in `github:owner/repository@ref`
                        form or an immutable public HTTPS `.tar.gz` URL
                      examples:
                        - github:BlocksOrg/agent-extensions@v1.2.0
                        - https://packages.example/extension-1.2.0.tar.gz
                - type: object
                  required:
                    - connection_id
                    - repository
                    - ref
                  properties:
                    connection_id:
                      type: string
                    repository:
                      type: string
                      example: owner/repository
                    ref:
                      type: string
                      example: v1.2.3
      responses:
        '200':
          description: Immutable source metadata for administrator confirmation
          content:
            application/json:
              schema:
                type: object
                required:
                  - source_ref
                  - sha256
                  - size_bytes
                properties:
                  source_ref:
                    type: string
                    format: uri
                  artifact_id:
                    type: string
                    format: uuid
                  resolved_commit:
                    type: string
                  sha256:
                    type: string
                    pattern: ^[a-f0-9]{64}$
                  size_bytes:
                    type: integer
                    maximum: 104857600
        '400':
          description: Source is unsafe, unreachable, too large, or invalid
components:
  securitySchemes:
    oauthDevice:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        OAuth 2.0 access token obtained through RFC 8628 at
        /api/auth/device/code and /api/auth/oauth2/token. The API enforces
        governance:read, session:write, and client-status:write as appropriate.

````