Makersclaw Store Registry
Every app in the Makersclaw App Store, in two views: the package Makersclaw installs, and the words, icon and screenshots marketing uses.
Auth
Every /v1 path needs a key, sent as a header:
Authorization: Bearer rk_<id>_<secret>
A key has one scope. marketing reads the apps. install reads the apps and the packages. Keys are issued by the Makersclaw team.
No key, a wrong key or an expired one: 401. A key whose scope does not cover the path: 403. A path this page does not list: 401, key or not.
Keep a key on a server. Never put it in a URL, a browser or a page.
Endpoints
GET /v1/apps.jsonmarketing or install · every app: its words, icon, screenshotsGET /v1/apps/<key>.jsonmarketing or install · one appGET /v1/apps/<key>/icon.jpg,page.md,screens/<name>.png,previews/<name>.htmlmarketing or install · the files one app namesGET /v1/index.jsoninstall · every package version, with its content hashGET /v1/packages/<key>/<version>.jsoninstall · one package, as Makersclaw installs itGET /health.jsonpublic · the commit this build is from
Examples
export REGISTRY_KEY=rk_… # from your server's secrets
# Every app
curl -s -H "Authorization: Bearer $REGISTRY_KEY" \
https://store.makersclaw.com/v1/apps.json
# One app, then its lead screenshot
curl -s -H "Authorization: Bearer $REGISTRY_KEY" \
https://store.makersclaw.com/v1/apps/whiteboard.json
curl -s -H "Authorization: Bearer $REGISTRY_KEY" -o board.png \
https://store.makersclaw.com/v1/apps/whiteboard/screens/3-boards.png
# Which build is live (no key)
curl -s https://store.makersclaw.com/health.json
Every path inside an answer is absolute. Put the host in front of it.
Sample data
The screenshots and previews show made-up people and companies. Their domains may belong to real businesses, so each screenshot and preview lists the third-party domains it shows as sample_domains: from its email addresses, links and text, leaving out reserved names (*.example, *.test) and the platforms apps connect to (such as google.com or linkedin.com).
Prefer screens where the list is empty. Never quote the names, emails or domains a screen shows in a post.
More
openapi.json: every endpoint and field. llms.txt: the same for an agent, with how to read the words.