From AI prototype to credible information system.Explore Go Live Fintech
App publishing

Build a capability.
Make it useful to other people.

Register your app with one call and it is on the Exchange at once, with a page of its own. The page shows what your app declares: what it does, what it can act on and how far a user may let it act.

Register with one call

Send your app's manifest to POST /api/v1/platform/register with your account's API key, which the Studio shows under API credentials. The account must be verified. market_listed: true is what puts the app on the Exchange; without it the app is registered but not listed.

Shell · register an app
curl -s -X POST https://priostack.com/api/v1/platform/register \
  -H "X-API-Key: $PRIOSTACK_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "id": "acme-notes",
    "name": "Acme Notes",
    "vendor": "Acme",
    "description": "Notes your agents can file.",
    "category": "Productivity",
    "version": "1.0.0",
    "platforms": ["web"],
    "base_url": "https://notes.acme.example",
    "market_price": "Free",
    "market_listed": true
  }'

The answer names the app and hands over its scoped token. The app uses that token for its own calls (heartbeat, token introspection, credit charges and refunds, events), so keep it on your server. Registering again returns the same token.

JSON · the answer
{"app_id":"acme-notes","scoped_token":"...","status":"registered",
 "accepted":{"capabilities":0,"events":0,"models":0,"scopes":0,"headless":true}}

A field the manifest does not define is refused with a 400 rather than dropped, so a typo cannot quietly remove part of your listing.

What the Exchange shows

Your card and your page at /exchange/<id> are built from the manifest when someone opens them, so a change appears as soon as you register again.

FieldWhere it shows
name, description, categoryThe card and the page. The category is also a filter on the Exchange.
vendor"By" line and publisher. A vendor that reads as Priostack is refused: that name is kept for Priostack's own apps.
version, platforms, market_priceThe page's facts, as you write them. The platforms are also a filter.
base_urlThe Open button. It must be an https:// address or a path on priostack.com.
readmeThe page, as plain text.
icon, colorThe app list in the Studio. The icon is an emoji or a short mark with no markup; the color is a hex or named color.

Priostack checks that a listing is well formed. It does not review the app, and it does not host it. Pages for apps by other publishers are kept out of search results.

Declare what it can do

Each capability in provides says what invoking it does in the world and how far a user may let it act. Your app's page lists every one, so a visitor reads them before granting anything.

JSON · part of a manifest
"provides": [{
  "id": "notes.file",
  "version": "1",
  "title": "File a note",
  "side_effect": "reversible_local",
  "max_autonomy": 2,
  "requires_confirmation": true
}]
  • side_effect is one of read_only, reversible_local, external_communication, financial_commitment, account_security or high_stakes. Describe the effect honestly: the platform sets its default confirmation from it.
  • max_autonomy is your ceiling, from 0 (suggest; the user acts) through 1 (prepare), 2 (act once the user agrees) and 3 (act inside a policy the user wrote) to 4 (act without asking). The user sets their own ceiling, and the lower of the two applies. Money and account-security capabilities cannot go above 2.
  • requires_confirmation asks the user every time.
  • scopes lists what the app says it wants from the platform, as opposed to what it does for a user. The page shows it; it does not limit the scoped token.

Models can be the application

A manifest's bundle lists the models your app is built from: processes, decisions, cases and interface models. Registering records that list; it deploys nothing. Deploy each model through the REST API (POST /api/v1/models), and connect any service of your own explicitly.

Update or remove a listing

Register again with the same id to change a listing in place. To take an app off the Exchange, register it with market_listed left out, or remove it.

Shell · list and remove
# Your registered apps, without their tokens
curl -s https://priostack.com/api/v1/platform/services -H "X-API-Key: $PRIOSTACK_KEY"

# Take one off the Exchange and out of the registry
curl -s -X DELETE https://priostack.com/api/v1/platform/services/acme-notes -H "X-API-Key: $PRIOSTACK_KEY

The full request and answer shapes are in the OpenAPI reference.

Make your capability easy to understand.

Begin with one clear job, an honest side effect and an explicit permission model.

Open the developer hub