B

Buildy HTTP API

REST declared

Details
URL
https://app.buildy.so
Spec
https://app.buildy.so/.well-known/openapi.json
Docs
https://buildy.so/build-http.md
Authentication
Buildy user token (bld_user_*) bearer declared
Authorization: Bearer <credential>

Two ways to obtain a bld_user_* token (see https://buildy.so/auth.md):

1. Device-pairing (RFC 8628-shaped): POST /api/pair/start returns { device_code, user_code, verification_url, polling_interval, expires_in }. Show the user_code to the human, direct them to verification_url (https://app.buildy.so/pair), then poll POST /api/pair/poll with { device_code }. On approval the next poll returns { status: "approved", token: "bld_user_..." } exactly once.

2. Browser-mint: sign in at https://app.buildy.so/auth/login, then POST /api/token with an optional label; the plaintext is returned once.

Anonymous app creation does not need a token — POST /app with the source and no Authorization header mints a one-app bld_app_* token (7-day TTL if unclaimed).