Deliver one exact reviewed revision
package main
import ( "fmt" "strings" "net/http" "io")
func main() {
url := "https://api.vampikez.fun/v1/sessions/9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731/publications/9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731"
payload := strings.NewReader("{ \"revision\": \"88b7d76865ac445123d1adb83bf4e8e039e16bc02c5c675725a62a849f514441\", \"title\": \"Rate limit the payments endpoint\", \"body\": \"Adds a sliding-window limiter of 100 requests per minute per API key on POST /charges.\\n\\nCloses PAY-4821.\", \"delivery\": \"pull_request\", \"draft\": true }")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "Bearer <token>") req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close() body, _ := io.ReadAll(res.Body)
fmt.Println(res) fmt.Println(string(body))
}const url = 'https://api.vampikez.fun/v1/sessions/9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731/publications/9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731';const options = { method: 'PUT', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"revision":"88b7d76865ac445123d1adb83bf4e8e039e16bc02c5c675725a62a849f514441","title":"Rate limit the payments endpoint","body":"Adds a sliding-window limiter of 100 requests per minute per API key on POST /charges.\n\nCloses PAY-4821.","delivery":"pull_request","draft":true}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request PUT \ --url https://api.vampikez.fun/v1/sessions/9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731/publications/9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731 \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "revision": "88b7d76865ac445123d1adb83bf4e8e039e16bc02c5c675725a62a849f514441", "title": "Rate limit the payments endpoint", "body": "Adds a sliding-window limiter of 100 requests per minute per API key on POST /charges.\n\nCloses PAY-4821.", "delivery": "pull_request", "draft": true }'The caller-owned Publication id is the recovery unit. Delivery defaults to a pull request. direct_branch is available to an App Session bound to a live repository grant; the server targets the Session-pinned base branch and OID, uses an exact expected-head lease, and leaves GitHub protections authoritative. A retry never adopts a live remote head or rebuilds a different commit.
Authorizations
Section titled “Authorizations”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters”A UUID identifying one Cloud resource; Session, Turn, Publication and Merge ids are minted by the caller so an ambiguous retry addresses the same durable command instead of creating a second one.
Example
9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731A UUID you mint and own; it is the idempotency key for creation and the address of every Turn, artifact and publication underneath
A UUID identifying one Cloud resource; Session, Turn, Publication and Merge ids are minted by the caller so an ambiguous retry addresses the same durable command instead of creating a second one.
Example
9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731A UUID you mint for this publish attempt; it is the idempotency and recovery key for the pull request
Request Bodyrequired
Section titled “Request Bodyrequired”Body of the idempotent publish command. The caller-owned Publication id is the recovery unit: a retry re-addresses the same command and never adopts a live remote head or rebuilds a different commit.
object
The exact review revision to publish; if the sandbox has changed since that review the command is refused rather than quietly rebuilt
Single-line pull-request title
Pull-request description in markdown; may be empty
Delivery mode. direct_branch never accepts a caller-selected ref: the server uses the exact base branch and OID pinned when the App Session was created, and it accepts no draft.
Whether to open the pull request as a draft; absent means a draft, which is the default. Refused with 400 invalid_request when delivery is direct_branch — a direct push opens no pull request, so there is nothing to draft and the field would be discarded.
Example
{ "revision": "88b7d76865ac445123d1adb83bf4e8e039e16bc02c5c675725a62a849f514441", "title": "Rate limit the payments endpoint", "body": "Adds a sliding-window limiter of 100 requests per minute per API key on POST /charges.\n\nCloses PAY-4821.", "delivery": "pull_request", "draft": true}Responses
Section titled “ Responses ”Idempotent replay
Envelope returned when a Publication is created or read.
object
The Publication as it stands after this request; a 201 means it was newly admitted and a 200 means an identical retry returned the stored command
object
The caller-owned Publication id, which is also the retry and recovery unit
Session whose reviewed changes are being published
admitted on acceptance, prepared once the local commit exists, attempted while the provider write is in flight, then terminal succeeded or failed
The review revision this Publication is permanently pinned to
Pull-request title as submitted
Immutable delivery mode included in the Publication idempotency identity
Present once status is succeeded. Pull-request delivery includes the WAMP-owned branch and pull request. Direct delivery includes only the server-pinned target branch and exact pushed commit; no pull-request fields are fabricated.
object
Lowercase hex 40-character Git object id naming an exact commit or tree in the source repository.
object
Coarse machine code for the failure; present when status is failed
object
When the Publication was admitted
Last durable state change of the command
When the Publication reached succeeded or failed
Example
{ "publication": { "id": "1e8d4b62-7f05-4c3a-9d21-6a48f0b7c952", "sessionId": "9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731", "status": "succeeded", "delivery": "pull_request", "revision": "88b7d76865ac445123d1adb83bf4e8e039e16bc02c5c675725a62a849f514441", "title": "Rate limit the payments endpoint", "result": { "delivery": "pull_request", "branch": "wamp/publications-v1/cloud-9f2b7c14-59d3-4f7a-b8e1-2a6c05-d8af1a5a", "commitSha": "281c35bbe1f0ed047127957c11858d1394722abf", "pullRequest": { "number": 482, "url": "https://github.com/acme/checkout-service/pull/482", "draft": true, "reused": false } }, "createdAt": "2026-08-12T09:52:31Z", "updatedAt": "2026-08-12T09:52:39Z", "completedAt": "2026-08-12T09:52:39Z" }}Publication admitted
Envelope returned when a Publication is created or read.
object
The Publication as it stands after this request; a 201 means it was newly admitted and a 200 means an identical retry returned the stored command
object
The caller-owned Publication id, which is also the retry and recovery unit
Session whose reviewed changes are being published
admitted on acceptance, prepared once the local commit exists, attempted while the provider write is in flight, then terminal succeeded or failed
The review revision this Publication is permanently pinned to
Pull-request title as submitted
Immutable delivery mode included in the Publication idempotency identity
Present once status is succeeded. Pull-request delivery includes the WAMP-owned branch and pull request. Direct delivery includes only the server-pinned target branch and exact pushed commit; no pull-request fields are fabricated.
object
Lowercase hex 40-character Git object id naming an exact commit or tree in the source repository.
object
Coarse machine code for the failure; present when status is failed
object
When the Publication was admitted
Last durable state change of the command
When the Publication reached succeeded or failed
Example
{ "publication": { "id": "1e8d4b62-7f05-4c3a-9d21-6a48f0b7c952", "sessionId": "9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731", "status": "succeeded", "delivery": "pull_request", "revision": "88b7d76865ac445123d1adb83bf4e8e039e16bc02c5c675725a62a849f514441", "title": "Rate limit the payments endpoint", "result": { "delivery": "pull_request", "branch": "wamp/publications-v1/cloud-9f2b7c14-59d3-4f7a-b8e1-2a6c05-d8af1a5a", "commitSha": "281c35bbe1f0ed047127957c11858d1394722abf", "pullRequest": { "number": 482, "url": "https://github.com/acme/checkout-service/pull/482", "draft": true, "reused": false } }, "createdAt": "2026-08-12T09:52:31Z", "updatedAt": "2026-08-12T09:52:39Z", "completedAt": "2026-08-12T09:52:39Z" }}Headers
Section titled “Headers”Malformed request
Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.
object
Stable machine code
The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request
Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value
Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.
object
Field path, outermost segment first. An integer segment is an array index.
Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.
Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId
Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.
Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.
The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer
object
Example
{ "error": "invalid_request"}No bearer was presented (bearer_credential_required), or the one presented is expired, revoked or for another audience (invalid_or_expired_credential)
Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.
object
Stable machine code
The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request
Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value
Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.
object
Field path, outermost segment first. An integer segment is an array index.
Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.
Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId
Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.
Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.
The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer
object
Example
{ "error": "bearer_credential_required"}Live installation, scope or organization policy denies the operation
Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.
object
Stable machine code
The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request
Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value
Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.
object
Field path, outermost segment first. An integer segment is an array index.
Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.
Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId
Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.
Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.
The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer
object
Example
{ "error": "insufficient_scope", "requiredScope": "wamp.cloud.sessions:create"}The resource is missing or inaccessible
Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.
object
Stable machine code
The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request
Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value
Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.
object
Field path, outermost segment first. An integer segment is an array index.
Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.
Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId
Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.
Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.
The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer
object
Example
{ "error": "cloud_session_not_found"}Idempotency, lifecycle, revision or single-flight conflict
Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.
object
Stable machine code
The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request
Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value
Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.
object
Field path, outermost segment first. An integer segment is an array index.
Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.
Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId
Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.
Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.
The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer
object
Example
{ "error": "cloud_session_conflict"}The request body was never read. Either the Content-Type is not a JSON media type — bodies are parsed only under application/json and RFC 6839 application/*+json — or its content encoding or charset was refused. unsupported_media_type echoes the type you sent in mediaType. Malformed JSON under an accepted media type is a different answer: 400 malformed_request_body.
Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.
object
Stable machine code
The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request
Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value
Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.
object
Field path, outermost segment first. An integer segment is an array index.
Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.
Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId
Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.
Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.
The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer
object
Example
{ "error": "unsupported_media_type", "mediaType": "application/x-www-form-urlencoded"}The pre-authentication edge budget or durable human-membership/App-installation budget is exhausted
Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.
object
Stable machine code
The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request
Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value
Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.
object
Field path, outermost segment first. An integer segment is an array index.
Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.
Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId
Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.
Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.
The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer
object
Example
{ "error": "cloud_rate_limit_exceeded", "retryAfterSeconds": 3}Headers
Section titled “Headers”IETF HTTPAPI structured quota policy
IETF HTTPAPI structured current service limit
The request was accepted and something on our side failed while answering it. Nothing about the request needs to change; the same call may succeed on retry. Retry cautiously, with backoff — a non-idempotent command may have taken effect before the fault.
Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.
object
Stable machine code
The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request
Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value
Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.
object
Field path, outermost segment first. An integer segment is an array index.
Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.
Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId
Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.
Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.
The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer
object
Example
{ "error": "internal_error"}A retryable condition: a workspace, runtime or provider that is not available yet, or service_unavailable while the service restarts for a release or its database cannot serve the request in time. Retry after the Retry-After this response carries.
Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.
object
Stable machine code
The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request
Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value
Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.
object
Field path, outermost segment first. An integer segment is an array index.
Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.
Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId
Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.
Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.
The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer
object
Example
{ "error": "cloud_workspace_unavailable"}