Skip to main content
GET
Say what a source is, and whether installing it needs trust

Authorizations

Authorization
string
header
required

Enforced on every transport, with no exempt operation. A person's request — over the default local unix socket exactly as over a TCP listener — must carry a JWT issued by the configured identity provider, which the host verifies itself against that issuer's key set: signature, issuer, expiry, and the person and organisation it names. Requests without a valid one receive 401 NRY-0011. The socket's file permissions are transport and are not an authorisation.

Query Parameters

source
string
required

An absolute local path, or a registry/module reference.

Maximum string length: 1024

Response

What that source is.

What a source turns out to be, learned without compiling it, importing it or downloading it.

source
string
required

The CANONICAL form of the source, and what an install must be started with: an absolute path for a local directory or file, the reference unchanged for a module. A consent surface that names one artifact and installs another is the one thing it may not do, so the caller carries this value through to installPackage rather than the word somebody typed.

name
string
required

The package name.

kind
enum<string>
required

resources installs instantly; code and both carry Go source and cost a rebuild and a binary swap. Reported as code for a module reference nothing has downloaded yet, which is the safe side of a guess nobody can make without fetching.

Available options:
resources,
code,
both
requiresFetch
boolean
required

The source is a module reference whose real kind and claims stay unknown until it is downloaded. A caller asking a person for consent says so rather than describing contents nobody has read.

requiresTrust
boolean
required

Installing this needs an acknowledgement: true for anything carrying compiled Go code, and equally true for a resources-only package declaring a hook, since a hook is an executable narya runs through the shell with no sandbox. A resources-only package with no hooks is never gated.