> ## Documentation Index
> Fetch the complete documentation index at: https://docs.instacloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Apply batch

> **Token scope:** `account` · `org` · `project` — read-only tokens refused (not a GET).

Write a batch of user secrets, then redeploy the compute services those values reach, one deploy per service. Entries are reported written individually and services are reported deployed, started, skipped or failed individually, because the writes commit before the deploys run and a failed deploy never rolls a value back. `skipDeploy` writes without deploying. `excludeFromDeploy` drops services the caller is deploying itself; `deployOnly` names the services to deploy and ignores derivation, which is how a failed deploy is retried with no entries. A rename writes no env, so it deploys nothing on its own and needs no `deploy` grant — a batch that both renames and writes still deploys, for the write. Gated on what the body contains: `secrets.write` for any set or delete, `service.rename` for a rename, `deploy` only for what can actually deploy. A project-scoped entry is authorized against every branch, since that is where its value lands. Deploying a stopped service starts it. A suspended service is skipped instead of deployed: a deploy would invalidate the RAM snapshot suspension exists to preserve, so it is left untouched and reported with reason `suspended`.



## OpenAPI

````yaml /openapi/project.json post /projects/{projectId}/apply
openapi: 3.1.0
info:
  title: InstaCloud API — Project level
  version: 0.1.0
  description: >-
    Endpoints under `/projects/{projectId}`: branches, services, deploys,
    secrets, databases, storage, cron, observability, governance. Callable with
    any token whose binding covers the project.


    Generated from the platform's own OpenAPI document
    (https://api.instacloud.com/openapi.json); see the [API
    overview](/reference/api/overview) for authentication and token scopes.
servers:
  - url: https://api.instacloud.com
    description: InstaCloud
security:
  - bearerAuth: []
tags:
  - name: Projects
    description: Projects inside an organization.
  - name: Branches
    description: >-
      Branch environments of a project: isolated database, storage and compute
      per branch.
  - name: Services
    description: 'Services on a branch: compute, postgres, storage and managed databases.'
  - name: Deploy
    description: Deploy an image or a source to a compute service.
  - name: Compute
    description: Build output of a compute service.
  - name: Secrets
    description: User secrets, service credentials and how they bind into compute env.
  - name: Database
    description: Postgres databases, extensions, credentials and ad-hoc SQL.
  - name: Storage
    description: Objects in a storage service.
  - name: Backups
    description: Database backups and restores.
  - name: Cron
    description: Scheduled HTTP calls against a service or an external URL.
  - name: Observability
    description: Logs, metrics, deploy events and database insight.
  - name: Governance
    description: Per-project agent policy and the approval queue.
  - name: Audit
    description: The project's event timeline, including agent-ingested events.
  - name: Domains
    description: >-
      Domains bought through InstaCloud, bring-your-own zones and their DNS
      records.
  - name: Billing
    description: Usage, cycles, invoices and credits.
  - name: Templates
    description: Deploy a template into a project.
paths:
  /projects/{projectId}/apply:
    post:
      tags:
        - Secrets
      summary: Apply batch
      description: >-
        **Token scope:** `account` · `org` · `project` — read-only tokens
        refused (not a GET).


        Write a batch of user secrets, then redeploy the compute services those
        values reach, one deploy per service. Entries are reported written
        individually and services are reported deployed, started, skipped or
        failed individually, because the writes commit before the deploys run
        and a failed deploy never rolls a value back. `skipDeploy` writes
        without deploying. `excludeFromDeploy` drops services the caller is
        deploying itself; `deployOnly` names the services to deploy and ignores
        derivation, which is how a failed deploy is retried with no entries. A
        rename writes no env, so it deploys nothing on its own and needs no
        `deploy` grant — a batch that both renames and writes still deploys, for
        the write. Gated on what the body contains: `secrets.write` for any set
        or delete, `service.rename` for a rename, `deploy` only for what can
        actually deploy. A project-scoped entry is authorized against every
        branch, since that is where its value lands. Deploying a stopped service
        starts it. A suspended service is skipped instead of deployed: a deploy
        would invalidate the RAM snapshot suspension exists to preserve, so it
        is left untouched and reported with reason `suspended`.
      operationId: applyBatch
      parameters:
        - schema:
            format: uuid
            type: string
          in: path
          name: projectId
          required: true
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                branch:
                  description: branch name (default branch if omitted)
                  type: string
                entries:
                  maxItems: 600
                  type: array
                  items:
                    anyOf:
                      - type: object
                        properties:
                          kind:
                            type: string
                            enum:
                              - set
                          name:
                            type: string
                          value:
                            type: string
                          branch:
                            type: string
                          service:
                            type: string
                        required:
                          - kind
                          - name
                          - value
                      - type: object
                        properties:
                          kind:
                            type: string
                            enum:
                              - delete
                          name:
                            type: string
                          branch:
                            type: string
                          service:
                            type: string
                        required:
                          - kind
                          - name
                      - type: object
                        properties:
                          kind:
                            type: string
                            enum:
                              - rename
                          serviceId:
                            type: string
                          name:
                            maxLength: 256
                            type: string
                        required:
                          - kind
                          - serviceId
                          - name
                skipDeploy:
                  type: boolean
                excludeFromDeploy:
                  maxItems: 100
                  type: array
                  items:
                    type: string
                deployOnly:
                  maxItems: 100
                  type: array
                  items:
                    type: string
              required:
                - entries
        required: true
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  entries:
                    type: array
                    items:
                      type: object
                      properties:
                        name:
                          type: string
                        written:
                          type: boolean
                      required:
                        - name
                        - written
                  services:
                    type: array
                    items:
                      type: object
                      properties:
                        serviceId:
                          type: string
                        result:
                          anyOf:
                            - type: string
                              enum:
                                - deployed
                            - type: string
                              enum:
                                - started
                            - type: string
                              enum:
                                - skipped
                            - type: string
                              enum:
                                - failed
                        reason:
                          type: string
                      required:
                        - serviceId
                        - result
                required:
                  - entries
                  - services
        '202':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApprovalRequired'
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    ApprovalRequired:
      type: object
      properties:
        status:
          type: string
          enum:
            - approval_required
        approvalId:
          format: uuid
          type: string
        action:
          description: the gated action, or a comma-joined compound set — prefer `actions`
          type: string
        actions:
          description: every capability this approval covers
          type: array
          items:
            type: string
        message:
          type: string
        url:
          description: the console page where a project admin reviews this request
          type: string
        nextActions:
          type: array
          items:
            $ref: '#/components/schemas/NextAction'
    Error:
      type: object
      properties:
        error:
          type: string
      required:
        - error
    NextAction:
      type: object
      properties:
        op:
          description: >-
            Neutral logical action id, e.g. "service.add" — NOT an operationId
            or a CLI/MCP tool name; each client maps it to its own surface.
          type: string
        reason:
          description: Natural-language, human/LLM-facing "why do this now".
          type: string
        args:
          description: >-
            Suggested, flat named arguments; "<placeholder>"s where a value is
            unknown.
          type: object
          additionalProperties: true
        gated:
          description: True if the action passes a governance gate.
          type: boolean
      required:
        - op
        - reason
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Session access JWT or an API token (`insta_<prefix>_<secret>`).

````