Reference

Store API

The JSON API an Aworg installs from. No key needed to read.

Everything is under /api/v1, answers in JSON, and needs no authentication to read.

GET /api/v1/packages?type=skill&q=dashboard&sort=popular&page=1
GET /api/v1/packages?name=weather
  • type: skill, tool, persona. Leave it out for all types.
  • q: words to match against name, description and author.
  • name: an exact name, across every type. This is how a bare aworg get weather finds out whether there's one match or several.
  • sort: popular (the default), new or name.
  • 100 results per page.
{
  "total": 1,
  "page": 1,
  "packages": [
    {
      "id": "tools/weather",
      "name": "weather",
      "type": "tool",
      "label": "Weather",
      "summary": "Looking up the weather anywhere by name...",
      "owner": "kevin",
      "latest": "1.0.0",
      "sha256": "9f2c...",
      "size": 5120,
      "install_dir": "capabilities",
      "url": "https://aworg.com/tools/weather",
      "download": "https://aworg.com/api/v1/packages/tools/weather/download"
    }
  ]
}

One package

GET /api/v1/packages/tools/weather

This returns the same fields, plus details (type-specific: a tool's list of tools, a persona's colours and avatar) and versions, newest first, each with its sha256 and whether it was withdrawn (yanked).

Download

GET /api/v1/packages/tools/weather/download
GET /api/v1/packages/tools/weather/download?version=1.0.0

This returns the zip. The response headers carry X-Package-Sha256, X-Package-Version and X-Package-Type. Check the SHA-256 against the one from the package endpoint before unpacking. Without version, you get the latest version that hasn't been withdrawn.