> ## Documentation Index
> Fetch the complete documentation index at: https://docs.springwinter.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Springwinter REST API — Complete Reference Overview

> Explore the Springwinter REST API (v0.1.0, OAS 3.1) — programmatic access to every control-plane feature, from deployments to billing.

The Springwinter REST API (version 0.1.0, OpenAPI Specification 3.1) is available at `https://springwinter.dev/api` and gives you programmatic access to every feature exposed by the control plane — deploying services, managing environment variables, reading logs and metrics, connecting AWS accounts, and more. You can explore and call the API interactively at [https://springwinter.dev/docs/api](https://springwinter.dev/docs/api) after signing in at [/auth](https://springwinter.dev/auth).

## Base URL

All API endpoints share a single base URL:

```
https://springwinter.dev
```

Prepend this to every path shown in the reference. For example, the projects list endpoint is reachable at `https://springwinter.dev/api/projects`.

## API Version

The current API version is **0.1.0**. The version is reflected in the OpenAPI document served at `https://springwinter.dev/docs/api`.

## Authentication

The API supports two authentication methods:

* **Bearer token** — recommended for all automated and programmatic access. Create a token in **Settings → API Tokens**, then pass it in the `Authorization` header.
* **Cookie session + CSRF token** — used by the Springwinter browser dashboard. Sign in via `POST /api/session`, then fetch a CSRF token from `GET /api/csrf` and include it as `X-CSRF-Token` on every mutating request.

See the [Authentication](/api-reference/authentication) page for full details and code examples.

## Request Format

For `POST`, `PATCH`, and `PUT` requests, send a JSON body and include the `Content-Type: application/json` header:

```bash theme={null}
curl -X POST https://springwinter.dev/api/projects \
  -H "Authorization: Bearer YOUR_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"name": "my-project"}'
```

`GET` and `DELETE` requests do not require a request body.

## Response Format

All responses are JSON. The API follows standard HTTP status code conventions:

| Status Code | Meaning |
| - | - |
| `200 OK` | Request succeeded; response body contains the result. |
| `201 Created` | Resource was successfully created; response body contains the new resource. |
| `204 No Content` | Request succeeded; no response body (common for `DELETE`). |
| `400 Bad Request` | The request body or parameters are invalid. |
| `401 Unauthorized` | No valid session cookie or bearer token was provided. |
| `403 Forbidden` | The CSRF token is missing or invalid (session-based requests only). |
| `404 Not Found` | The requested resource does not exist or is not visible to your account. |

## Resources

Use the cards below to jump directly to the reference section for each resource group.

<CardGroup cols={2}>
  <Card title="Session" icon="arrow-right-to-bracket" href="/api-reference/session">
    Sign in, retrieve the current user, and sign out.
  </Card>

  <Card title="API Tokens" icon="key" href="/api-reference/api-tokens">
    Create and revoke long-lived API bearer tokens.
  </Card>

  <Card title="Projects" icon="folder" href="/api-reference/projects">
    Manage projects and HTTPS certificates.
  </Card>

  <Card title="Web Servers" icon="server" href="/api-reference/web-servers">
    Deploy, redeploy, and manage containerised web servers.
  </Card>

  <Card title="Workers" icon="gear" href="/api-reference/workers">
    Deploy and manage background worker services.
  </Card>

  <Card title="Static Websites" icon="globe" href="/api-reference/static-websites">
    Deploy static sites backed by S3 and CloudFront.
  </Card>

  <Card title="Caches" icon="database" href="/api-reference/caches">
    Provision and manage Valkey (Redis-compatible) caches.
  </Card>

  <Card title="Storage" icon="hard-drive" href="/api-reference/storage">
    Create and manage private S3 storage buckets.
  </Card>

  <Card title="Bedrock" icon="microchip" href="/api-reference/bedrock">
    Configure and access AWS Bedrock AI models.
  </Card>

  <Card title="AWS" icon="aws" href="/api-reference/aws">
    Connect and verify your AWS account.
  </Card>

  <Card title="GitHub" icon="github" href="/api-reference/github">
    Manage GitHub App installations and repository access.
  </Card>
</CardGroup>
