Admin API
Allowlist, pause, and cancel. Bearer token. Operator only.
The admin API is on the receiver. A repository owner does not call it. The portal does not hand out autofeat-admin-token and does not call these routes as the owner. See Portal.
Set the token in the environment. Do not paste it into a shell history file you share.
export AUTOFEAT_ADMIN_TOKEN='...'
export RECEIVER='https://autofeat-web-774341561528.us-central1.run.app'Every call sends Authorization: Bearer $AUTOFEAT_ADMIN_TOKEN. A bad token returns 401 and {"result":"unauthorized"}. Admin or the control object down returns 503 and {"result":"unavailable"}. The secret name is autofeat-admin-token.
Read control and spend
curl -sS -H "Authorization: Bearer $AUTOFEAT_ADMIN_TOKEN" \
"$RECEIVER/admin/control"
curl -sS -H "Authorization: Bearer $AUTOFEAT_ADMIN_TOKEN" \
"$RECEIVER/admin/spend"GET /admin/control returns the allowlist, pause_all, and related control fields. GET /admin/spend returns reserved and settled USD, open runs, and per-run rows.
Allow an installation
The path id is the GitHub App installation id for one account. It is not the public App id 5103856. Each org or user install has its own id. Read it from the installation webhook or from GET /admin/control after the first delivery.
# INSTALLATION_ID is a placeholder. Replace it with the real installation id.
curl -sS -X PUT \
-H "Authorization: Bearer $AUTOFEAT_ADMIN_TOKEN" \
-H "Content-Type: application/json" \
-d '{"allowed":true}' \
"$RECEIVER/admin/installations/${INSTALLATION_ID}"The path must be an integer greater than 0. "allowed": false removes that id.
Until the installation is allowlisted, webhooks log ignored_installation and return HTTP 200 with no run.
Allow a repository
curl -sS -X PUT \
-H "Authorization: Bearer $AUTOFEAT_ADMIN_TOKEN" \
-H "Content-Type: application/json" \
-d '{"repository":"owner/repo","allowed":true}' \
"$RECEIVER/admin/repositories"The body field is repository as owner/name, plus allowed. The API stores the name in lower case and rejects ... Extra JSON fields are refused.
Until the repository is allowlisted, webhooks log ignored_repository.
Pause every repository
curl -sS -X PUT \
-H "Authorization: Bearer $AUTOFEAT_ADMIN_TOKEN" \
-H "Content-Type: application/json" \
-d '{"paused":true}' \
"$RECEIVER/admin/pause"{"paused":true} sets pause_all. New deliveries log ignored_paused. {"paused":false} clears it. This is not the pull-request label autofeat:pause.
Cancel one run
curl -sS -X POST \
-H "Authorization: Bearer $AUTOFEAT_ADMIN_TOKEN" \
-H "Content-Type: application/json" \
-d '{"run_id":"REPLACE_WITH_RUN_ID"}' \
"$RECEIVER/admin/cancel"run_id must match ^[A-Za-z0-9._:-]{1,128}$. Read last_run_id from the sticky comment. See Reading the state comment.