Raster API
Persistent personal computers for agents. A machine is the core resource: a durable computer that can be stopped and started without losing its files.
Authentication. Every request carries an organization API key as Authorization: Bearer sk_.... Create one in the dashboard; the secret is shown once.
Errors. Every non-2xx response is the same envelope: { error: { code, message, request_id, details?, quota? } }. Switch on code, which is a closed set; message is written for a person and may be reworded.
Repeating a request. Any unsafe request accepts an Idempotency-Key header, and that is what makes retrying one safe: a repeat replays the first response instead of creating a second machine. Reusing a key with a different body is a conflict.
Lists. Every list is cursor-paginated and answers { data, next_cursor, has_more }. A cursor is opaque; pass back what the last page returned and never construct one.
https://api.raster.shMachines
The core resource. Creating one boots a computer; stopping it keeps the disk and deleting it destroys it. Forking copies a disk into a second machine that owes the first nothing afterwards.
- GETList machines
/v1/machines - POSTCreate a machine
/v1/machines - GETGet a machine
/v1/machines/{machine_id} - DELETEDelete a machine
/v1/machines/{machine_id} - PATCHUpdate a machine
/v1/machines/{machine_id} - POSTStart a stopped machine
/v1/machines/{machine_id}/start - POSTStop a machine, keeping its files
/v1/machines/{machine_id}/stop - POSTRestart a machine
/v1/machines/{machine_id}/restart - POSTFork a machine
/v1/machines/{machine_id}/fork - GETList a machine's events
/v1/machines/{machine_id}/events - GETList what has been done to a machine
/v1/machines/{machine_id}/activity
Images
The server-owned catalog of base disk images a machine boots from. machines.create accepts any id listed here and uses the image marked default when a request names none. Deprecated images stay listed, with deprecated_at set, because existing machines still reference them.
Computer control
Driving a machine the way a person would: its screen, pointer, keyboard, clipboard, terminals, files and browser. Every coordinate is in the pixel space of the machine’s current display, and one outside it is rejected rather than clamped.
- GETTake a screenshot
/v1/machines/{machine_id}/screenshot - GETGet the display geometry
/v1/machines/{machine_id}/display - POSTRun a command
/v1/machines/{machine_id}/exec - GETRead the clipboard
/v1/machines/{machine_id}/clipboard - PUTWrite the clipboard
/v1/machines/{machine_id}/clipboard - POSTCreate a realtime connection ticket
/v1/machines/{machine_id}/connect - POSTMove the pointer
/v1/machines/{machine_id}/mouse/move - POSTClick the pointer
/v1/machines/{machine_id}/mouse/click - POSTDrag the pointer
/v1/machines/{machine_id}/mouse/drag - POSTScroll the wheel
/v1/machines/{machine_id}/mouse/scroll - POSTType text
/v1/machines/{machine_id}/keyboard/type - POSTPress a key
/v1/machines/{machine_id}/keyboard/key - POSTPress a key combination
/v1/machines/{machine_id}/keyboard/hotkey - POSTResize the display
/v1/machines/{machine_id}/display/resize - POSTRestart the desktop session
/v1/machines/{machine_id}/desktop/restart - GETList terminals
/v1/machines/{machine_id}/terminals - POSTOpen a terminal
/v1/machines/{machine_id}/terminals - DELETEClose a terminal
/v1/machines/{machine_id}/terminals/{terminal_id} - GETList a directory
/v1/machines/{machine_id}/files - GETRead a file
/v1/machines/{machine_id}/files/content - PUTWrite a file
/v1/machines/{machine_id}/files/content - POSTOpen a URL in the browser
/v1/machines/{machine_id}/browser/open - GETList open browser tabs
/v1/machines/{machine_id}/browser/tabs
Sessions and input
A connection to a machine, and the single input lease that hangs off it. At most one session may send input at a time, which is what makes human takeover safe rather than interleaved.
- GETList sessions
/v1/sessions - POSTOpen a session
/v1/sessions - DELETEClose a session
/v1/sessions/{session_id} - GETGet the current input lease
/v1/machines/{machine_id}/input-lease - POSTAcquire or renew the input lease
/v1/machines/{machine_id}/input-lease - DELETERelease the input lease
/v1/machines/{machine_id}/input-lease
Snapshots
Captured disks. A capture holds files, installed software and browser profile data, and holds no RAM and no live process state. Captures of one machine form a chain and only the newest can be deleted.
- GETList snapshots
/v1/snapshots - POSTCapture a snapshot
/v1/snapshots - GETGet a snapshot
/v1/snapshots/{snapshot_id} - DELETEDelete a snapshot
/v1/snapshots/{snapshot_id} - POSTRestore a machine from a snapshot
/v1/machines/{machine_id}/restore
Templates
Named starting states. A template is a snapshot with a name and an organization behind it, so a team can agree on what its standard box is.
- GETList templates
/v1/templates - POSTCreate a template
/v1/templates - GETGet a template
/v1/templates/{template_id} - DELETEDelete a template
/v1/templates/{template_id}
Published ports
Publishing a guest port at its own https hostname. Private by default; the credential is in the response that creates it and nowhere else.
- GETList a machine's published ports
/v1/machines/{machine_id}/ports - POSTPublish a port at its own HTTPS URL
/v1/machines/{machine_id}/ports - GETGet a published port
/v1/machines/{machine_id}/ports/{preview_id} - DELETEUnpublish a port
/v1/machines/{machine_id}/ports/{preview_id} - GETList all published ports
/v1/ports
Secrets
Values delivered into tmpfs inside a machine. A stored value is never returned - there is no read route here and no field one could travel in - and a snapshot, fork or template does not carry it.
- GETList a machine's secret names
/v1/machines/{machine_id}/secrets - PUTStore a secret on a machine
/v1/machines/{machine_id}/secrets - DELETERevoke a secret
/v1/machines/{machine_id}/secrets/{name} - GETList all secret names
/v1/secrets
Usage
The metered record behind a bill: raw records for a period, and the same records bucketed for charting. This is the source of truth, not the provider’s copy.
Plans
The server-owned catalog of plans, entitlements and rates. No price, allowance or weight is hardcoded in any client, so an older SDK can display a newer catalog.