Validate an inline manifest without firing a run
Dry-run validator. Runs the same preflight as POST /api/runs/inline — manifest shape, input against the manifest schema, and integration readiness — but never inserts a shadow package, never fires the pipeline, and never consumes run credits. Returns 200 { valid: true } on success, 400 problem+json for validation failures (with the accumulated validation errors). Lets developers iterate on a manifest without leaving run history behind.
Rate limit: shares the same per-user bucket as POST /api/runs/inline (INLINE_RUN_LIMITS.rate_per_min). Iterative validation calls count against the same quota as actual runs — tight loops can trigger 429. Caller-authored inline manifests require the read permission for each dependency type. Existing dependencies must be readable in an accessible source space (API keys remain pinned to their space), or belong to the readable system/catalog sources. Missing read permissions return 403; inaccessible existing sources return 404, before readiness checks or creation of a run. Nonexistent dependencies retain the normal validation errors. Permission: agents:write and agents:run — composing a manifest is authoring, launching it is running. A caller holding agents:run without agents:write — the operator and runner presets, an API key scoped to agents:run — is refused.
/api/runs/inline/validateCookie session from Better Auth. Requires X-Org-Id header for org-scoped routes.
In: cookie
Header Parameters
Organization ID. Required for cookie auth. Not needed for API key auth (org resolved from key).
uuidSpace ID. Required for space-scoped routes (agents, runs, schedules, and space-scoped module routes). Not needed for API key auth (space resolved from key).
End-user ID (eu_ prefix) to execute the request on behalf of. API key auth only — rejected with 400 on cookie auth.
API version override (format: YYYY-MM-DD). Defaults to the org's pinned version or the current platform version.
Request Body
application/json
curl -X POST "https://your-instance/api/runs/inline/validate" \ -H "Content-Type: application/json" \ -d '{ "manifest": {}, "prompt": "string" }'{
"valid": true
}{
"type": "http://example.com",
"title": "string",
"status": 0,
"detail": "string",
"instance": "string",
"code": "string",
"request_id": "string",
"param": "string",
"retry_after": 0,
"errors": [
{
"field": "string",
"code": "string",
"message": "string",
"title": "string",
"candidate_connections": [
{
"id": "string",
"label": "string",
"account_id": "string",
"owned_by_actor": true,
"needs_reconnection": true
}
],
"connection_id": "string",
"missing_scopes": [
"string"
],
"owned_by_actor": true,
"required_scopes": [
"string"
],
"auth_key": "string",
"required_auth_key": "string",
"available_auth_keys": [
"string"
],
"connect_url": "http://example.com",
"expiresAt": "2019-08-24T14:15:22Z",
"packageId": "string"
}
]
}{
"type": "https://docs.appstrate.dev/errors/unauthorized",
"title": "Unauthorized",
"status": 401,
"detail": "Invalid or missing session",
"code": "unauthorized",
"request_id": "req_abc123"
}{
"type": "https://docs.appstrate.dev/errors/forbidden",
"title": "Forbidden",
"status": 403,
"detail": "Insufficient permissions",
"code": "forbidden",
"request_id": "req_abc123"
}{
"type": "https://docs.appstrate.dev/errors/not-found",
"title": "Not Found",
"status": 404,
"detail": "Resource not found",
"code": "not_found",
"request_id": "req_abc123"
}{
"type": "https://docs.appstrate.dev/errors/rate-limited",
"title": "Rate Limited",
"status": 429,
"detail": "Too many requests. Please try again shortly.",
"code": "rate_limited",
"request_id": "req_abc123",
"retry_after": 30
}{
"type": "https://docs.appstrate.dev/errors/internal-error",
"title": "Internal Server Error",
"status": 500,
"detail": "An unexpected error occurred. Please try again or contact support.",
"code": "internal_error",
"request_id": "req_abc123"
}