Skip to content

Deliver one exact reviewed revision

PUT
/v1/sessions/{sessionId}/publications/{publicationId}
curl --request PUT \
--url https://api.vampikez.fun/v1/sessions/9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731/publications/9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731 \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "revision": "88b7d76865ac445123d1adb83bf4e8e039e16bc02c5c675725a62a849f514441", "title": "Rate limit the payments endpoint", "body": "Adds a sliding-window limiter of 100 requests per minute per API key on POST /charges.\n\nCloses PAY-4821.", "delivery": "pull_request", "draft": true }'

The caller-owned Publication id is the recovery unit. Delivery defaults to a pull request. direct_branch is available to an App Session bound to a live repository grant; the server targets the Session-pinned base branch and OID, uses an exact expected-head lease, and leaves GitHub protections authoritative. A retry never adopts a live remote head or rebuilds a different commit.

sessionId
required

A UUID identifying one Cloud resource; Session, Turn, Publication and Merge ids are minted by the caller so an ambiguous retry addresses the same durable command instead of creating a second one.

string format: uuid
Example
9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731

A UUID you mint and own; it is the idempotency key for creation and the address of every Turn, artifact and publication underneath

publicationId
required

A UUID identifying one Cloud resource; Session, Turn, Publication and Merge ids are minted by the caller so an ambiguous retry addresses the same durable command instead of creating a second one.

string format: uuid
Example
9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731

A UUID you mint for this publish attempt; it is the idempotency and recovery key for the pull request

Media typeapplication/json

Body of the idempotent publish command. The caller-owned Publication id is the recovery unit: a retry re-addresses the same command and never adopts a live remote head or rebuilds a different commit.

object
revision
required

The exact review revision to publish; if the sandbox has changed since that review the command is refused rather than quietly rebuilt

string
/^[a-f0-9]{64}$/
title
required

Single-line pull-request title

string
>= 1 characters <= 256 characters
body
required

Pull-request description in markdown; may be empty

string
<= 65536 characters
delivery

Delivery mode. direct_branch never accepts a caller-selected ref: the server uses the exact base branch and OID pinned when the App Session was created, and it accepts no draft.

string
default: pull_request
Allowed values: pull_request direct_branch
draft

Whether to open the pull request as a draft; absent means a draft, which is the default. Refused with 400 invalid_request when delivery is direct_branch — a direct push opens no pull request, so there is nothing to draft and the field would be discarded.

boolean
default: true
Example
{
"revision": "88b7d76865ac445123d1adb83bf4e8e039e16bc02c5c675725a62a849f514441",
"title": "Rate limit the payments endpoint",
"body": "Adds a sliding-window limiter of 100 requests per minute per API key on POST /charges.\n\nCloses PAY-4821.",
"delivery": "pull_request",
"draft": true
}

Idempotent replay

Media typeapplication/json

Envelope returned when a Publication is created or read.

object
publication
required

The Publication as it stands after this request; a 201 means it was newly admitted and a 200 means an identical retry returned the stored command

object
id
required

The caller-owned Publication id, which is also the retry and recovery unit

string format: uuid
sessionId
required

Session whose reviewed changes are being published

string format: uuid
status
required

admitted on acceptance, prepared once the local commit exists, attempted while the provider write is in flight, then terminal succeeded or failed

string
Allowed values: admitted prepared attempted succeeded failed
revision
required

The review revision this Publication is permanently pinned to

string
/^[a-f0-9]{64}$/
title
required

Pull-request title as submitted

string
delivery
required

Immutable delivery mode included in the Publication idempotency identity

string
Allowed values: pull_request direct_branch
result

Present once status is succeeded. Pull-request delivery includes the WAMP-owned branch and pull request. Direct delivery includes only the server-pinned target branch and exact pushed commit; no pull-request fields are fabricated.

object
delivery
required
string
Allowed values: pull_request direct_branch
branch
required
string
commitSha
required

Lowercase hex 40-character Git object id naming an exact commit or tree in the source repository.

string
/^[a-f0-9]{40}$/
pullRequest
object
number
required
integer
url
required
string format: uri
draft
required
boolean
reused
required
boolean
lastError

Coarse machine code for the failure; present when status is failed

object
code
string
createdAt
required

When the Publication was admitted

string format: date-time
updatedAt
required

Last durable state change of the command

string format: date-time
completedAt

When the Publication reached succeeded or failed

string format: date-time
Example
{
"publication": {
"id": "1e8d4b62-7f05-4c3a-9d21-6a48f0b7c952",
"sessionId": "9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731",
"status": "succeeded",
"delivery": "pull_request",
"revision": "88b7d76865ac445123d1adb83bf4e8e039e16bc02c5c675725a62a849f514441",
"title": "Rate limit the payments endpoint",
"result": {
"delivery": "pull_request",
"branch": "wamp/publications-v1/cloud-9f2b7c14-59d3-4f7a-b8e1-2a6c05-d8af1a5a",
"commitSha": "281c35bbe1f0ed047127957c11858d1394722abf",
"pullRequest": {
"number": 482,
"url": "https://github.com/acme/checkout-service/pull/482",
"draft": true,
"reused": false
}
},
"createdAt": "2026-08-12T09:52:31Z",
"updatedAt": "2026-08-12T09:52:39Z",
"completedAt": "2026-08-12T09:52:39Z"
}
}

Publication admitted

Media typeapplication/json

Envelope returned when a Publication is created or read.

object
publication
required

The Publication as it stands after this request; a 201 means it was newly admitted and a 200 means an identical retry returned the stored command

object
id
required

The caller-owned Publication id, which is also the retry and recovery unit

string format: uuid
sessionId
required

Session whose reviewed changes are being published

string format: uuid
status
required

admitted on acceptance, prepared once the local commit exists, attempted while the provider write is in flight, then terminal succeeded or failed

string
Allowed values: admitted prepared attempted succeeded failed
revision
required

The review revision this Publication is permanently pinned to

string
/^[a-f0-9]{64}$/
title
required

Pull-request title as submitted

string
delivery
required

Immutable delivery mode included in the Publication idempotency identity

string
Allowed values: pull_request direct_branch
result

Present once status is succeeded. Pull-request delivery includes the WAMP-owned branch and pull request. Direct delivery includes only the server-pinned target branch and exact pushed commit; no pull-request fields are fabricated.

object
delivery
required
string
Allowed values: pull_request direct_branch
branch
required
string
commitSha
required

Lowercase hex 40-character Git object id naming an exact commit or tree in the source repository.

string
/^[a-f0-9]{40}$/
pullRequest
object
number
required
integer
url
required
string format: uri
draft
required
boolean
reused
required
boolean
lastError

Coarse machine code for the failure; present when status is failed

object
code
string
createdAt
required

When the Publication was admitted

string format: date-time
updatedAt
required

Last durable state change of the command

string format: date-time
completedAt

When the Publication reached succeeded or failed

string format: date-time
Example
{
"publication": {
"id": "1e8d4b62-7f05-4c3a-9d21-6a48f0b7c952",
"sessionId": "9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731",
"status": "succeeded",
"delivery": "pull_request",
"revision": "88b7d76865ac445123d1adb83bf4e8e039e16bc02c5c675725a62a849f514441",
"title": "Rate limit the payments endpoint",
"result": {
"delivery": "pull_request",
"branch": "wamp/publications-v1/cloud-9f2b7c14-59d3-4f7a-b8e1-2a6c05-d8af1a5a",
"commitSha": "281c35bbe1f0ed047127957c11858d1394722abf",
"pullRequest": {
"number": 482,
"url": "https://github.com/acme/checkout-service/pull/482",
"draft": true,
"reused": false
}
},
"createdAt": "2026-08-12T09:52:31Z",
"updatedAt": "2026-08-12T09:52:39Z",
"completedAt": "2026-08-12T09:52:39Z"
}
}
Location
string

Malformed request

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "invalid_request"
}

No bearer was presented (bearer_credential_required), or the one presented is expired, revoked or for another audience (invalid_or_expired_credential)

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "bearer_credential_required"
}

Live installation, scope or organization policy denies the operation

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "insufficient_scope",
"requiredScope": "wamp.cloud.sessions:create"
}

The resource is missing or inaccessible

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "cloud_session_not_found"
}

Idempotency, lifecycle, revision or single-flight conflict

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "cloud_session_conflict"
}

The request body was never read. Either the Content-Type is not a JSON media type — bodies are parsed only under application/json and RFC 6839 application/*+json — or its content encoding or charset was refused. unsupported_media_type echoes the type you sent in mediaType. Malformed JSON under an accepted media type is a different answer: 400 malformed_request_body.

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "unsupported_media_type",
"mediaType": "application/x-www-form-urlencoded"
}

The pre-authentication edge budget or durable human-membership/App-installation budget is exhausted

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "cloud_rate_limit_exceeded",
"retryAfterSeconds": 3
}
Retry-After
integer
>= 1
RateLimit-Policy
string

IETF HTTPAPI structured quota policy

RateLimit
string

IETF HTTPAPI structured current service limit

The request was accepted and something on our side failed while answering it. Nothing about the request needs to change; the same call may succeed on retry. Retry cautiously, with backoff — a non-idempotent command may have taken effect before the fault.

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "internal_error"
}

A retryable condition: a workspace, runtime or provider that is not available yet, or service_unavailable while the service restarts for a release or its database cannot serve the request in time. Retry after the Retry-After this response carries.

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "cloud_workspace_unavailable"
}
Retry-After
integer