Skip to main content
POST
Publish an instance version

Behavior

This request runs the instance’s gate eval scenarios with real model calls before it releases anything, and can take up to 50 minutes. It is exempt from the 30-second request timeout; keep the connection open. The gate rules, every outcome, and the waiver are on Versions and publish.

Authorizations

Authorization
string
header
required

Send the key as Authorization: Bearer <key>. Two kinds of key exist.

Organization keys are issued in the portal (Settings, then API keys), each bound to one environment, shaped nx_<environment slug>_<64 hex>. They carry no capabilities and pass every capability check, with one exception: routes under /api/v1/records, /api/v1/engines/{id}/opportunities, /api/v1/graph and /api/v1/catalog/documents accept an organization key only when its environment is live, and refuse any other with 403 scoped_key_required. Revocation takes effect within 60 seconds.

Scoped keys are issued by Nexio on request, shaped nxsk_v1_<24 hex key id>_<43 character secret>. Each is bound to one org, one environment, a set of engines and a set of capabilities. A malformed, unknown or revoked nxsk_ key fails with 401 and is never retried as an organization key. Revocation takes effect on the next request. A scoped key without a route's capability gets 403 insufficient_capability; a scoped key not bound to the engine gets 403 engine_binding_forbidden.

Key-grantable capabilities: engines:read, runs:write, runs:read, runs:defensibility:read, runs:test, catalog:read, catalog:documents:read, webhooks:manage, conversations:use, conversations:export, records:read, records:opportunities:run, actions:write, actions:read, graph:read, records:analyze.

Routes that accept organization keys only (every scoped key gets 403 insufficient_capability): environment management, engine create, update, configuration and publish, and conversation instance authoring. Each operation description names the capability a scoped key needs.

Path Parameters

instance_slug
string
required

Conversation instance identifier slug (e.g. platform-assistant).

Body

application/json
changelog
string
waived_by
string
waive_reason
string

Response

The released version (or the idempotent no-op). released_at has whole-second precision. On a new release it is the time the response was built and can differ slightly from the version list. When already_released is true, changelog and published_by are the latest version's, not this request's.

version
integer
required
config_hash
string
required
released_at
string<date-time>
required
changelog
string
required
already_released
boolean
published_by
string
Last modified on September 25, 2026