Skip to content

Overview

End-to-end encrypted sync for AI harness skills and instructions.

Every JSON response uses the envelope { ok, data | error, meta }. Error codes: https://docs.skillpouch.net/errors.

Authentication. CLI devices send Authorization: DPoP <access token> plus a DPoP proof (RFC 9449) signed by the device key. Browsers use the session cookie plus a DPoP proof from the key bound with POST /v1/session/bind, and send Skillpouch-Client: web on writes. Fetch a nonce from GET /v1/dpop/nonce.

DPoP-bound access token + DPoP proof

Security scheme type: http

Security scheme type: apiKey

Cookie parameter name: sp.session_token