Skip to main content
The Shipyard REST API lets you manage projects, trigger and inspect builds, fetch deployments, and interact with the CI/CD pipeline programmatically. All API endpoints are mounted under the /api prefix, with the exception of the /health route.

Base URL

Replace localhost:8080 with your server’s address when deploying to a VPS or using a tunnel. All REST endpoints follow the pattern http://<your-server>/api/<resource>.

Authentication

Most endpoints require a JSON Web Token (JWT) issued after completing the GitHub OAuth flow. Pass the token as a Bearer credential in the Authorization header:
The token is validated on every request by the isAuth middleware. If the header is missing, malformed, or the token is expired, the server responds with 401.
Two endpoint groups do not require a JWT: the /api/auth routes (which are part of the OAuth flow itself) and the /health and /api utility routes. The webhook endpoint uses HMAC-SHA256 signature verification instead of JWT — see the Webhook page for details.

Endpoints

All endpoints return JSON. The tables below list every route, whether it requires authentication, and a short description.

Auth

Repos

Projects

Builds

Deployments

Webhook

Health

Error responses

All error responses follow a consistent JSON shape:
The data field is optional and typically contains validation errors from express-validator when a request body fails validation. Common HTTP status codes:

Explore by resource

Auth

GitHub OAuth flow and JWT issuance

Repos

Browse GitHub organizations and repositories

Projects

Create, update, and delete connected projects

Builds

Trigger rebuilds and inspect build records

Deployments

Fetch deployments and roll back to earlier versions

Webhook

GitHub push event signature verification and build triggering