The API and Automations are the supported channels for programmatic use. Do not script against the app or automate interactive CLI surfaces.
Prerequisites
Before using the API:- Add a repository and configure an environment.
- Connect credentials for at least one coding agent.
- Create an API key.
Authentication
Send the key as a bearer token. The key identifies the organization, so no separate organization header is required. Every endpoint in the API Reference supports API key authentication.
Keep API keys in a secret manager. Do not place them in repositories, client-side code, or workspace prompts.
Repository branches
List a connected repository’s branches before choosing a task’s starting point:?q=feature to search branch prefixes without loading every branch in large repositories. Repository IDs come from GET /v1/replica/repositories.
Create a workspace
First, list environments and choose the environment that contains the repositories and configuration for the task.preparing workspace immediately. Poll GET /v1/replica/{id} or stream GET /v1/replica/{id}/events until the workspace becomes active and the agent finishes.
Send follow-up instructions with POST /v1/replica/{id}/messages. Sleeping workspaces wake automatically when you interact with them. Message requests automatically restore archived workspaces. API reads leave them archived. A message accepted before a concurrent archive remains queued and runs after the workspace is restored.
GET /v1/replica returns newest created_at first. With status=archived, results are ordered by most recent interaction instead: messages sent and agent turns completed. Waking a workspace does not change its position.
Workspace lifecycle
Event streaming requires an active workspace. Send a message to wake a suspended workspace before opening its event stream.
Environments API
Environments define the repositories, variables, files, skills, MCP servers, hooks, warm pools, and system prompt used to create workspaces. Use the/v1/environments endpoints to list, create, and update environments. Nested endpoints manage variables, files, skills, MCP servers, warm hooks, and start hooks. Personal environments use scope: "user"; organization environments use scope: "org".
The Global environment applies organization defaults to every workspace. Its metadata cannot be edited, but its nested resources can be managed through the same endpoints.
Environment access
Environment endpoints requireenvironments:read to list, view, select, or use an environment and environments:write to change it or its nested configuration. Automation endpoints require automations:read and automations:write the same way, and creating a shared automation needs organization-wide automations:write. Write includes Read.
Manage roles and grants in the dashboard. See Access.
Media
Use the media URL endpoints to retrieve screenshots, recordings, generated images, audio, and other shareable assets. Request a short-lived download URL for files or a preview URL when a browser should render the object inline. Media access is organization-scoped. Public access uses revocable bearer URLs: images uploaded from workspaces always get one, video and audio can opt in, and HTML never does.Automations API
The/v1/automations endpoints create and manage scheduled, GitHub, GitLab, Slack, Sentry, and webhook-triggered agent runs.
Create an automation
Create an automation with a name, prompt, trigger, and environment. Optional settings choose the coding agent, model, thinking level, workspace size, lifecycle policy, debounce window, and GitHub checks.API versioning
POST /v1/replica accepts X-Replicas-Api-Version.
Pin a dated version so future API changes do not alter an integration unexpectedly.
API reference
Open the API Reference tab for endpoint schemas, parameters, responses, and interactive request examples generated fromopenapi.json.
Workspace identity
GET /v1/environments/{environmentId}/workload-identity returns the workspace identity issuer, discovery, and JWKS URLs. Tokens are minted inside the workspace, not through this API. HTTP MCPs can use auth: { "type": "workspace_identity", "audience": "YOUR_AUDIENCE" } instead of saved headers.