List the files in a package artifact
Flat index of every file in the package artifact — one entry per real file, sorted by path; directories are not synthesized. Text files up to 1 MiB carry their full content in inline while the response's cumulative inline budget lasts; inline is never a truncated prefix, so an entry without it must be fetched from GET /api/packages/{scope}/{name}/files/content. Read-only. Rate-limited to 50 requests/minute.
/api/packages/{scope}/{name}/filesCookie session from Better Auth. Requires X-Org-Id header for org-scoped routes.
In: cookie
Path Parameters
Package scope (e.g. @myorg)
^@[a-z0-9][a-z0-9-]*$Package name
Query Parameters
Which definition to read. OMITTED reads the one that exists for this caller — the author's live draft (the stored artifact overlaid with the authoritative manifest.json / primary content from the database) when they may WRITE the package, the latest published version otherwise, and the draft again when nothing is published yet. An EXPLICIT draft is an author's act and is reserved to callers who may write the package: 403 draft_not_writable otherwise. Any other value is resolved as a version spec (exact version, dist-tag, or semver range) and returns exactly the published bytes, with no overlay. A system package ships its definition with the platform and has no published versions, so every selector but the named draft reads the same stored tree — nobody writes a platform-shipped package, so ?version=draft answers 403 draft_not_writable there like anywhere else.
Header Parameters
Organization ID. Required for cookie auth. Not needed for API key auth (org resolved from key).
uuidSpace ID. Required for space-scoped routes (agents, runs, schedules, and space-scoped module routes). Not needed for API key auth (space resolved from key).
Entity-tag of a cached copy. A match yields 304 Not Modified.
curl -X GET "https://your-instance/api/packages/string/string/files"{
"object": "list",
"data": [
{
"path": "string",
"size": 0,
"media_kind": "text",
"inline": "string"
}
],
"hasMore": true
}{
"type": "https://docs.appstrate.dev/errors/validation-failed",
"title": "Validation Failed",
"status": 400,
"detail": "name: Invalid input: expected string, received undefined (+2 more)",
"code": "validation_failed",
"request_id": "req_abc123",
"errors": [
{
"field": "name",
"code": "required",
"message": "Invalid input: expected string, received undefined"
},
{
"field": "email",
"code": "invalid_format",
"message": "Invalid email address"
},
{
"field": "age",
"code": "invalid_type",
"message": "Invalid input: expected number, received string"
}
]
}{
"type": "https://docs.appstrate.dev/errors/unauthorized",
"title": "Unauthorized",
"status": 401,
"detail": "Invalid or missing session",
"code": "unauthorized",
"request_id": "req_abc123"
}{
"type": "https://docs.appstrate.dev/errors/forbidden",
"title": "Forbidden",
"status": 403,
"detail": "Insufficient permissions",
"code": "forbidden",
"request_id": "req_abc123"
}{
"type": "https://docs.appstrate.dev/errors/not-found",
"title": "Not Found",
"status": 404,
"detail": "Resource not found",
"code": "not_found",
"request_id": "req_abc123"
}{
"type": "https://docs.appstrate.dev/errors/package-archive-unreadable",
"title": "Package Archive Unreadable",
"status": 422,
"detail": "The package archive expands past the 50 MB decompression limit and was refused (decompressed-budget-exceeded). Republish the package from bytes that fit the limit.",
"code": "package_archive_unreadable",
"request_id": "req_abc123"
}{
"type": "https://docs.appstrate.dev/errors/rate-limited",
"title": "Rate Limited",
"status": 429,
"detail": "Too many requests. Please try again shortly.",
"code": "rate_limited",
"request_id": "req_abc123",
"retry_after": 30
}{
"type": "http://example.com",
"title": "string",
"status": 0,
"detail": "string",
"instance": "string",
"code": "string",
"request_id": "string",
"param": "string",
"retry_after": 0,
"errors": [
{
"field": "string",
"code": "string",
"message": "string",
"title": "string",
"candidate_connections": [
{
"id": "string",
"label": "string",
"account_id": "string",
"owned_by_actor": true,
"needs_reconnection": true
}
],
"connection_id": "string",
"missing_scopes": [
"string"
],
"owned_by_actor": true,
"required_scopes": [
"string"
],
"auth_key": "string",
"required_auth_key": "string",
"available_auth_keys": [
"string"
],
"connect_url": "http://example.com",
"expiresAt": "2019-08-24T14:15:22Z",
"packageId": "string"
}
]
}