Skip to main content

Choose the API origin

Production: https://app.ohmyho.st. Use https://dev.app.ohmyho.st only when you deliberately selected the development platform. Paths below already include /v1. Create your user token from Profile → API Tokens or the CLI, then load it through your shell or automation platform’s secret storage.
The response lists projects available to that token’s organization. Use the returned IDs for later requests. Empty results mean no visible projects, not a failed authentication.

Requests that change state

Use the exact method, schema and permissions in the endpoint reference. Supply Idempotency-Key where required and retain it with the original request. After an uncertain response, replay the same key and payload; a new key can create new work. Accepted asynchronous mutations return an operation ID. Read GET /v1/operations/{operation_id} and follow its polling guidance. Operation success still requires checking the expected application outcome.

Errors and pagination

An error uses application/problem+json with a stable code, retryable, suggested_action and request_id; type links the page for that code. Decide by code, not HTTP status alone. 402 means credits, Paid access or a Stop budget block the request. 409 means a prerequisite must change, for example github_connection_required, mail_domain_required, deployment_plan_expired or etag_mismatch. Repeat an unchanged request only when retryable is true; for 429, wait for Retry-After. An uncertain mutation keeps its original request and key; never retry every error as new work. List endpoints return their documented cursor. Send that cursor on the next request and stop when it is absent. Errors, limits and polling.

Download the contract

Both API documents describe the actual public REST contract, including each endpoint’s authentication. Interactive browser-session endpoints cannot be used by substituting an API key. All product actions in the portal, CLI and MCP use this same service.