multipart/form-data, and realtime streams Server-Sent Events.
Base URL
Every endpoint in this reference is relative to:https://blob.squarecloud.app/v1, and it takes the same API key.
Authentication
Create an API key in your account security settings and send it in theAuthorization header of every request. The Bearer prefix is optional.
Your first request
Account Information returns your profile, your plan and every application and database you own. It needs a key with theaccount:read scope.
401 ACCESS_DENIED, the key is missing or not recognized. If you get 403 MISSING_SCOPE, the key works but lacks account:read.
Response format
A successful call answers2xx with "status": "success" and, when there is something to return, the data in response:
{ "status": "success" }. A failed call answers 4xx or 5xx with "status": "error" and a code to branch on:
snake_case. Every code, with what to do about it, is in Errors.
IDs
- Applications and databases have a 32-character hexadecimal id, such as
a1b2c3d4e5f64a7b8c9d0e1f2a3b4c5d. Get them from Account Information or from the address of the resource in the dashboard. - An application shared with you through a workspace is addressed as
<appId>-<workspaceId>in the path, for example/v2/apps/<appId>-<workspaceId>/status. - Workspaces have a 32-character hexadecimal id. Older workspaces keep a 40-character one.
Limits
Each account has a budget of requests per 60 seconds, set by its plan, and some endpoints have their own limit, stated on their page. See Limitations and restrictions for the values and Errors for how429 works.
OpenAPI specification
The whole API is described in an OpenAPI document athttps://api.squarecloud.app/v2/openapi.json. Import it into Postman or Insomnia, or generate a client from it.
Next steps
Authentication and scopes
Pick the scopes each integration needs.
Error codes
Every code the API returns and how to handle it.
Upload an application
Deploy a zip with one request.
Rate limits
Request budgets per plan.

