curl --request POST \
--url https://api.instacloud.com/projects/{projectId}/apply \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"entries": [
{
"kind": "set",
"name": "<string>",
"value": "<string>",
"branch": "<string>",
"service": "<string>"
}
],
"branch": "<string>",
"skipDeploy": true,
"excludeFromDeploy": [
"<string>"
],
"deployOnly": [
"<string>"
]
}
'import requests
url = "https://api.instacloud.com/projects/{projectId}/apply"
payload = {
"entries": [
{
"kind": "set",
"name": "<string>",
"value": "<string>",
"branch": "<string>",
"service": "<string>"
}
],
"branch": "<string>",
"skipDeploy": True,
"excludeFromDeploy": ["<string>"],
"deployOnly": ["<string>"]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
entries: [
{
kind: 'set',
name: '<string>',
value: '<string>',
branch: '<string>',
service: '<string>'
}
],
branch: '<string>',
skipDeploy: true,
excludeFromDeploy: ['<string>'],
deployOnly: ['<string>']
})
};
fetch('https://api.instacloud.com/projects/{projectId}/apply', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.instacloud.com/projects/{projectId}/apply",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'entries' => [
[
'kind' => 'set',
'name' => '<string>',
'value' => '<string>',
'branch' => '<string>',
'service' => '<string>'
]
],
'branch' => '<string>',
'skipDeploy' => true,
'excludeFromDeploy' => [
'<string>'
],
'deployOnly' => [
'<string>'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.instacloud.com/projects/{projectId}/apply"
payload := strings.NewReader("{\n \"entries\": [\n {\n \"kind\": \"set\",\n \"name\": \"<string>\",\n \"value\": \"<string>\",\n \"branch\": \"<string>\",\n \"service\": \"<string>\"\n }\n ],\n \"branch\": \"<string>\",\n \"skipDeploy\": true,\n \"excludeFromDeploy\": [\n \"<string>\"\n ],\n \"deployOnly\": [\n \"<string>\"\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.instacloud.com/projects/{projectId}/apply")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"entries\": [\n {\n \"kind\": \"set\",\n \"name\": \"<string>\",\n \"value\": \"<string>\",\n \"branch\": \"<string>\",\n \"service\": \"<string>\"\n }\n ],\n \"branch\": \"<string>\",\n \"skipDeploy\": true,\n \"excludeFromDeploy\": [\n \"<string>\"\n ],\n \"deployOnly\": [\n \"<string>\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.instacloud.com/projects/{projectId}/apply")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"entries\": [\n {\n \"kind\": \"set\",\n \"name\": \"<string>\",\n \"value\": \"<string>\",\n \"branch\": \"<string>\",\n \"service\": \"<string>\"\n }\n ],\n \"branch\": \"<string>\",\n \"skipDeploy\": true,\n \"excludeFromDeploy\": [\n \"<string>\"\n ],\n \"deployOnly\": [\n \"<string>\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"entries": [
{
"name": "<string>",
"written": true
}
],
"services": [
{
"serviceId": "<string>",
"result": "deployed",
"reason": "<string>"
}
]
}{
"status": "approval_required",
"approvalId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"action": "<string>",
"actions": [
"<string>"
],
"message": "<string>",
"url": "<string>",
"nextActions": [
{
"op": "<string>",
"reason": "<string>",
"args": {},
"gated": true
}
]
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}Apply batch
Token scope: account · org · project — read-only tokens refused (not a GET).
Write a batch of user secrets, then redeploy the compute services those values reach, one deploy per service. Entries are reported written individually and services are reported deployed, started, skipped or failed individually, because the writes commit before the deploys run and a failed deploy never rolls a value back. skipDeploy writes without deploying. excludeFromDeploy drops services the caller is deploying itself; deployOnly names the services to deploy and ignores derivation, which is how a failed deploy is retried with no entries. A rename writes no env, so it deploys nothing on its own and needs no deploy grant — a batch that both renames and writes still deploys, for the write. Gated on what the body contains: secrets.write for any set or delete, service.rename for a rename, deploy only for what can actually deploy. A project-scoped entry is authorized against every branch, since that is where its value lands. Deploying a stopped service starts it. A suspended service is skipped instead of deployed: a deploy would invalidate the RAM snapshot suspension exists to preserve, so it is left untouched and reported with reason suspended.
curl --request POST \
--url https://api.instacloud.com/projects/{projectId}/apply \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"entries": [
{
"kind": "set",
"name": "<string>",
"value": "<string>",
"branch": "<string>",
"service": "<string>"
}
],
"branch": "<string>",
"skipDeploy": true,
"excludeFromDeploy": [
"<string>"
],
"deployOnly": [
"<string>"
]
}
'import requests
url = "https://api.instacloud.com/projects/{projectId}/apply"
payload = {
"entries": [
{
"kind": "set",
"name": "<string>",
"value": "<string>",
"branch": "<string>",
"service": "<string>"
}
],
"branch": "<string>",
"skipDeploy": True,
"excludeFromDeploy": ["<string>"],
"deployOnly": ["<string>"]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
entries: [
{
kind: 'set',
name: '<string>',
value: '<string>',
branch: '<string>',
service: '<string>'
}
],
branch: '<string>',
skipDeploy: true,
excludeFromDeploy: ['<string>'],
deployOnly: ['<string>']
})
};
fetch('https://api.instacloud.com/projects/{projectId}/apply', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.instacloud.com/projects/{projectId}/apply",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'entries' => [
[
'kind' => 'set',
'name' => '<string>',
'value' => '<string>',
'branch' => '<string>',
'service' => '<string>'
]
],
'branch' => '<string>',
'skipDeploy' => true,
'excludeFromDeploy' => [
'<string>'
],
'deployOnly' => [
'<string>'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.instacloud.com/projects/{projectId}/apply"
payload := strings.NewReader("{\n \"entries\": [\n {\n \"kind\": \"set\",\n \"name\": \"<string>\",\n \"value\": \"<string>\",\n \"branch\": \"<string>\",\n \"service\": \"<string>\"\n }\n ],\n \"branch\": \"<string>\",\n \"skipDeploy\": true,\n \"excludeFromDeploy\": [\n \"<string>\"\n ],\n \"deployOnly\": [\n \"<string>\"\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.instacloud.com/projects/{projectId}/apply")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"entries\": [\n {\n \"kind\": \"set\",\n \"name\": \"<string>\",\n \"value\": \"<string>\",\n \"branch\": \"<string>\",\n \"service\": \"<string>\"\n }\n ],\n \"branch\": \"<string>\",\n \"skipDeploy\": true,\n \"excludeFromDeploy\": [\n \"<string>\"\n ],\n \"deployOnly\": [\n \"<string>\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.instacloud.com/projects/{projectId}/apply")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"entries\": [\n {\n \"kind\": \"set\",\n \"name\": \"<string>\",\n \"value\": \"<string>\",\n \"branch\": \"<string>\",\n \"service\": \"<string>\"\n }\n ],\n \"branch\": \"<string>\",\n \"skipDeploy\": true,\n \"excludeFromDeploy\": [\n \"<string>\"\n ],\n \"deployOnly\": [\n \"<string>\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"entries": [
{
"name": "<string>",
"written": true
}
],
"services": [
{
"serviceId": "<string>",
"result": "deployed",
"reason": "<string>"
}
]
}{
"status": "approval_required",
"approvalId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"action": "<string>",
"actions": [
"<string>"
],
"message": "<string>",
"url": "<string>",
"nextActions": [
{
"op": "<string>",
"reason": "<string>",
"args": {},
"gated": true
}
]
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}Authorizations
Session access JWT or an API token (insta_<prefix>_<secret>).