Mini apps
API
Create, update and send mini apps for review from your own scripts or CI.
Mini apps API
Everything the dashboard does with your apps is also an API, so you can deploy from a script, a build step or CI.
Authenticate with an API key from Dashboard β API keys:
Authorization: Bearer $TOKENHARBOR_API_KEY
A key only ever manages your own apps. Requests and responses are JSON.
The app object
{
"slug": "menu-reader",
"url": "https://tokenharbor.ai/a/menu-reader",
"name": "Menu reader",
"tagline": "Point your camera at a menu",
"icon": "π",
"color": "#c2410c",
"system_prompt": "You help travellers read menusβ¦",
"status": "draft",
"review_note": null,
"html_bytes": 20562,
"updated_at": "2026-09-23T08:00:00Z",
"published_at": null,
"submitted_at": null,
"html": "<!doctype html>β¦"
}
status is one of draft, in_review, changes_requested, published, published_with_unreviewed_changes, taken_down. html is included when you ask for one app.
Create an app
curl -X POST https://tokenharbor.ai/api/miniapps \
-H "Authorization: Bearer $TOKENHARBOR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"slug": "menu-reader", "name": "Menu reader"}'
slug is the address: 3β32 lowercase letters, digits and hyphens. You can also send tagline, icon, color, system_prompt and html. You can keep up to 20 apps.
Update the page
curl -X PATCH https://tokenharbor.ai/api/miniapps/menu-reader \
-H "Authorization: Bearer $TOKENHARBOR_API_KEY" \
-H "Content-Type: application/json" \
--data "$(jq -Rs '{html: .}' index.html)"
Send any of name, tagline, icon, color, system_prompt, html. An update changes only your draft: you can try it at the app's address straight away, and nobody else sees it until it is reviewed. Updating an app that is in review takes it out of review.
Send for review
curl -X POST https://tokenharbor.ai/api/miniapps/menu-reader/submit \
-H "Authorization: Bearer $TOKENHARBOR_API_KEY"
Read and delete
curl https://tokenharbor.ai/api/miniapps \
-H "Authorization: Bearer $TOKENHARBOR_API_KEY" # all your apps
curl https://tokenharbor.ai/api/miniapps/menu-reader \
-H "Authorization: Bearer $TOKENHARBOR_API_KEY" # one, with its page
curl -X DELETE https://tokenharbor.ai/api/miniapps/menu-reader \
-H "Authorization: Bearer $TOKENHARBOR_API_KEY"
Errors
Errors come back as {"error": {"code": "...", "message": "..."}} with a matching HTTP status: 400 for a field that does not fit, 401 without a valid key, 404 for an app that is not yours or does not exist, 409 for an address that is taken, 429 when you change things too quickly (30 a minute).