Discover capabilities available to this installation
package main
import ( "fmt" "net/http" "io")
func main() {
url := "https://api.vampikez.fun/v1/capabilities"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close() body, _ := io.ReadAll(res.Body)
fmt.Println(res) fmt.Println(string(body))
}const url = 'https://api.vampikez.fun/v1/capabilities';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://api.vampikez.fun/v1/capabilities \ --header 'Authorization: Bearer <token>'Returns only models, runtimes, environments and repository operations the current organization and installation may use. Provider credentials, pool members, image references and runner addresses are never returned.
Authorizations
Section titled “Authorizations”Responses
Section titled “ Responses ”Actor-filtered capabilities
object
What this exact organization and installation may actually use right now. Read it before choosing anything and never hardcode model, runtime or environment ids — provider credentials, pool membership and runner topology are deliberately absent.
object
Constant document marker, so a stored capability snapshot can be recognized out of context
Capability document version; a new integer would accompany a breaking reshape of this document, while new fields and enum values are additive within it
Organization these capabilities were resolved for — the same organization that will own any Session created with this credential
items are the WAMP catalog models this organization may select for the native agent, each with tier, context window and per-1K pricing when the Account knows it. Missing price fields mean price unknown, not free. defaults.slots names one model per purpose, already resolved: every slot carries a concrete id that is present in items, never null and never a model this organization cannot spend on. defaults.slots.agent is the model selected when a new native Session omits model; no intersection with items is needed. An organization entitled to no model gets no slots. defaults.enabled is the organization’s whole entitlement, of which items is the subset this deployment can route with tool use, which every native Run requires — prefer items.
object
Selectable agent runtimes with continuation fidelity and availability. modelSource: 'catalog' selects a WAMP model on the Session; runtime uses a separately connected vendor subscription; host runs a foreign agent loop on WAMP’s metered model plane and needs no vendor account. Omit the Session-level model for runtime and host; a bounded configCatalog may provide agent-owned model and setting choices to attach to initialTurn. Catalog absence means agent default only.
object
The one managed sandbox platform available to this organization, including workspace checkpoint limits, runtimes and compute availability. This entry is distinct from organization-owned revisioned environment objects selected on Session creation. Those objects are managed through /v1/environments and do not appear here.
object
Which repository sources may back a Session, and which deliveries this caller can actually reach. Every available here is scoped to the grants this installation holds, not to what the platform implements: all of them are false until an administrator has granted at least one repository, and one live grant reaches all of them. Read this before creating a Session — an organization that has granted nothing produces a Session that runs and reviews normally and fails for the first time at publish. Which refs may actually land is GitHub’s decision, expressed as branch protection on the repository.
object
Artifact paging and checkpoint size ceilings in bytes; content larger than a ceiling is bounded or omitted rather than silently truncated without notice
object
Request and page limits. Retained Session history is keyset-paginated and does not block creation.
object
Example
{ "capabilities": { "schema": "wamp.cloud-capabilities", "version": 1, "organizationId": "0b9a6f3e-5c21-4d78-9e64-8f1a2b7c3d05", "models": { "items": [ { "id": "claude-opus-5", "label": "Claude Opus 5", "provider": "anthropic", "description": "Claude flagship. Step-change over Opus 4.8 on deep reasoning and long-horizon agentic work at the same price. 1M context.", "tier": "powerful", "version": "GA", "showInUI": true, "contextWindow": 1000000, "maxOutput": 128000, "costPer1kInput": 0.005, "costPer1kOutput": 0.025 }, { "id": "gemini-3.6-flash", "label": "Gemini 3.6 Flash", "provider": "gemini", "description": "Google's default workhorse (Jul 2026). Strong coding and agentic work, cheaper output than 3.5 Flash. 1M context.", "tier": "balanced", "version": "GA", "showInUI": true, "contextWindow": 1048576, "maxOutput": 65536, "costPer1kInput": 0.0015, "costPer1kOutput": 0.0075 } ], "defaults": { "slots": { "chat": "claude-opus-5", "agent": "claude-opus-5", "agent-fast": "gemini-3.6-flash", "agent-powerful": "claude-opus-5", "background": "gemini-3.6-flash", "reasoning": "claude-opus-5", "generation": "gemini-3.6-flash" }, "enabled": [ "qwen3.8-max", "gemini-3.6-flash", "claude-sonnet-5-5", "claude-opus-5" ] } }, "runtimes": [ { "id": "wamp", "label": "WAMP", "modelSource": "catalog", "continuation": { "live": "exact", "checkpoint": "exact" }, "availability": { "state": "available" } }, { "id": "pi", "label": "Pi", "modelSource": "host", "continuation": { "live": "exact", "checkpoint": "exact" }, "availability": { "state": "available" } }, { "id": "claude-code", "label": "Claude Code", "modelSource": "runtime", "continuation": { "live": "exact", "checkpoint": "exact" }, "availability": { "state": "temporarily_unavailable", "retryAt": "2026-08-12T09:22:30Z" } } ], "environments": [ { "id": "managed", "label": "WAMP managed sandbox", "availability": { "state": "available" }, "default": true, "runtimes": [ "wamp", "pi", "claude-code" ], "workspace": { "checkpoint": "portable_tree", "maxCheckpointBytes": 268435456 } } ], "repositories": { "sources": [ { "kind": "public_https", "available": true }, { "kind": "github_repository_grant", "available": true, "discovery": "/v1/repositories" } ], "publications": [ { "kind": "github_draft_pull_request", "available": true }, { "kind": "github_direct_branch_push", "available": false } ], "merges": [ { "kind": "github_pull_request_merge", "available": true, "strategies": [ "merge", "squash", "rebase" ], "modes": [ "now", "when_ready" ] } ] }, "artifacts": { "maxPageSize": 100, "conversationCheckpointMaxBytes": 268435456, "workspaceCheckpointMaxBytes": 268435456 }, "limits": { "maxMessageCharacters": 100000, "maxPageSize": 100 } }}No bearer was presented (bearer_credential_required), or the one presented is expired, revoked or for another audience (invalid_or_expired_credential)
Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.
object
Stable machine code
The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request
Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value
Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.
object
Field path, outermost segment first. An integer segment is an array index.
Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.
Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId
Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.
Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.
The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer
object
Example
{ "error": "bearer_credential_required"}Live installation, scope or organization policy denies the operation
Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.
object
Stable machine code
The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request
Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value
Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.
object
Field path, outermost segment first. An integer segment is an array index.
Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.
Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId
Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.
Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.
The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer
object
Example
{ "error": "insufficient_scope", "requiredScope": "wamp.cloud.sessions:create"}The pre-authentication edge budget or durable human-membership/App-installation budget is exhausted
Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.
object
Stable machine code
The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request
Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value
Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.
object
Field path, outermost segment first. An integer segment is an array index.
Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.
Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId
Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.
Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.
The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer
object
Example
{ "error": "cloud_rate_limit_exceeded", "retryAfterSeconds": 3}Headers
Section titled “Headers”IETF HTTPAPI structured quota policy
IETF HTTPAPI structured current service limit
The request was accepted and something on our side failed while answering it. Nothing about the request needs to change; the same call may succeed on retry. Retry cautiously, with backoff — a non-idempotent command may have taken effect before the fault.
Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.
object
Stable machine code
The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request
Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value
Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.
object
Field path, outermost segment first. An integer segment is an array index.
Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.
Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId
Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.
Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.
The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer
object
Example
{ "error": "internal_error"}The bounded set of in-flight calls to the identity and catalog dependency behind this document is spent. Retry after the Retry-After: 2 this response carries; it is a refusal to queue, not an outage. While the service restarts for a release, or its database cannot serve the request in time, the code is service_unavailable, with the same header.
Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.
object
Stable machine code
The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request
Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value
Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.
object
Field path, outermost segment first. An integer segment is an array index.
Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.
Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId
Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.
Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.
The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer
object
Example
{ "error": "cloud_agent_catalog_unavailable"}