depot.dev
Depot exposes authenticated HTTP APIs at `https://api.depot.dev` for builds/CI/sandboxes plus Depot Cache and an OCI registry at `{orgId}.registry.depot.dev`, along with the `depot` CLI; authentication is via Depot bearer tokens (user, organization, project, pull where applicable), CLI login or `DEPOT_TOKEN`, and OIDC trust relationships for CI.
- Depot APIdiscovered
- Depot Cachediscovered
- Depot Registrydiscovered
- Depot CLIdiscovered
In the Depot account settings, use the API Tokens section to create a user access token, or run depot login locally to have Depot create and store one for the CLI. User tokens are tied to your Depot account and are recommended for local development, not CI.
Open Organization Settings, enter a description under API Tokens, and click Create token. This organization-scoped token can be used for the Depot API, Depot CI, Cache, Registry, Agents, and CLI automation.
Go to the Projects page, open a project, click Settings, then under Project Tokens create a token and copy it. Project tokens are scoped to a single project and are intended for container-build use cases, especially CI where OIDC is not available.
Generate a pull token with the Depot CLI using depot pull-token --project <project-id>. Pull tokens are short-lived, read-only, and only work for Depot Registry pulls.
Configure a trust relationship on a project in the Projects page: open the project, go to Settings, and add a provider under Trust Relationships. Depot supports GitHub Actions, CircleCI, Buildkite, and RWX. In CI, the job presents its provider OIDC identity and Depot exchanges it for a temporary token valid for that job.
Use a Depot GitHub Actions runner job with the automatic Depot Cache integration enabled; Depot injects a one-job cache token as the DEPOT_CACHE_TOKEN environment variable. This is not manually minted in the dashboard.
conventions · 1/7 published
- integrations.json——
- llms.txt✓https://depot.dev/llms.txt
- API catalog✗
/.well-known/api-catalog - OpenAPI document✗
/api/schema/, /openapi.json, /swagger.json, /api/openapi.json, or /v1/openapi.json - MCP server card✗
/.well-known/mcp/server-card.json - OAuth protected resource✗
/.well-known/oauth-protected-resource - Agent card✗
/.well-known/agent-card.json - Agent skills✗
/.well-known/agent-skills/index.json
Publish these signals → /publishing