curl --request POST \
--url https://api.checkfu.com/v1/blueprint-installations/apply \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'checkfu-version: <checkfu-version>' \
--data '
{
"files": {},
"available_references": [
{
"name": "<string>"
}
],
"credentialed": [
"<string>"
],
"agent_blueprint_release_id": null,
"webhook_secret_inputs": [
{
"requirement": "<string>",
"value": "<string>"
}
]
}
'import requests
url = "https://api.checkfu.com/v1/blueprint-installations/apply"
payload = {
"files": {},
"available_references": [{ "name": "<string>" }],
"credentialed": ["<string>"],
"agent_blueprint_release_id": None,
"webhook_secret_inputs": [
{
"requirement": "<string>",
"value": "<string>"
}
]
}
headers = {
"checkfu-version": "<checkfu-version>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'checkfu-version': '<checkfu-version>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
files: {},
available_references: [{name: '<string>'}],
credentialed: ['<string>'],
agent_blueprint_release_id: null,
webhook_secret_inputs: [{requirement: '<string>', value: '<string>'}]
})
};
fetch('https://api.checkfu.com/v1/blueprint-installations/apply', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.checkfu.com/v1/blueprint-installations/apply",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'files' => [
],
'available_references' => [
[
'name' => '<string>'
]
],
'credentialed' => [
'<string>'
],
'agent_blueprint_release_id' => null,
'webhook_secret_inputs' => [
[
'requirement' => '<string>',
'value' => '<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"checkfu-version: <checkfu-version>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.checkfu.com/v1/blueprint-installations/apply"
payload := strings.NewReader("{\n \"files\": {},\n \"available_references\": [\n {\n \"name\": \"<string>\"\n }\n ],\n \"credentialed\": [\n \"<string>\"\n ],\n \"agent_blueprint_release_id\": null,\n \"webhook_secret_inputs\": [\n {\n \"requirement\": \"<string>\",\n \"value\": \"<string>\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("checkfu-version", "<checkfu-version>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.checkfu.com/v1/blueprint-installations/apply")
.header("checkfu-version", "<checkfu-version>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"files\": {},\n \"available_references\": [\n {\n \"name\": \"<string>\"\n }\n ],\n \"credentialed\": [\n \"<string>\"\n ],\n \"agent_blueprint_release_id\": null,\n \"webhook_secret_inputs\": [\n {\n \"requirement\": \"<string>\",\n \"value\": \"<string>\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.checkfu.com/v1/blueprint-installations/apply")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["checkfu-version"] = '<checkfu-version>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"files\": {},\n \"available_references\": [\n {\n \"name\": \"<string>\"\n }\n ],\n \"credentialed\": [\n \"<string>\"\n ],\n \"agent_blueprint_release_id\": null,\n \"webhook_secret_inputs\": [\n {\n \"requirement\": \"<string>\",\n \"value\": \"<string>\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"id": "<string>",
"workspace_id": "<string>",
"blueprint_name": "<string>",
"agent_blueprint_release_id": "<string>",
"applied_version": 1,
"release_hash": "<string>",
"lifecycle": "planned",
"resolved_resources": [
{
"resource_kind": "<string>",
"logical_name": "<string>",
"resource_id": "<string>",
"ownership": "created",
"config_hash": "<string>",
"management": "adopted",
"manage_mode": "reconcile"
}
],
"missing_inputs": [
"<string>"
],
"history": [
{
"operation_id": "<string>",
"kind": "plan",
"release_hash": "<string>",
"at": "<string>"
}
],
"version": 1,
"created_at": "<string>",
"updated_at": "<string>",
"provenance": "client_asserted"
}{
"error": {
"type": "validation.malformed",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-malformed"
}
}{
"error": {
"type": "auth.invalid_key",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-invalid-key"
}
}{
"error": {
"type": "auth.disabled_tenancy",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-disabled-tenancy"
}
}{
"error": {
"type": "validation.not_found",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-not-found"
}
}{
"error": {
"type": "validation.conflict",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-conflict"
}
}{
"error": {
"type": "budget.exceeded",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#budget-exceeded"
}
}{
"error": {
"type": "runtime.internal",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#runtime-internal"
}
}Apply an AgentBlueprint package
Reconcile an immutable published AgentBlueprint package, or the dated inline-package compatibility request, into ordinary governed aggregates. Live Workspace authority resolves every reference and custody requirement. Automation-bound webhook SecretRequirements are supplied through the bounded, write-only webhook_secret_inputs sidecar for creation and managed secret rotation; an unchanged reapply may omit the sidecar, while a changed webhook declaration must supply its exact named requirement. Values are routed only to ordinary Automation create or patch operations and never appear in the package, plan, installation, or response. Returns the resulting BlueprintInstallation with created-versus-reused ownership and any still-owed inputs; accepts an optional Idempotency-Key.
Checkfu support posture: alpha; hosted. Required evidence journey: blueprint-authority. Deployment-specific readiness and the latest proven release are available from GET /v1/support/capabilities.
curl --request POST \
--url https://api.checkfu.com/v1/blueprint-installations/apply \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'checkfu-version: <checkfu-version>' \
--data '
{
"files": {},
"available_references": [
{
"name": "<string>"
}
],
"credentialed": [
"<string>"
],
"agent_blueprint_release_id": null,
"webhook_secret_inputs": [
{
"requirement": "<string>",
"value": "<string>"
}
]
}
'import requests
url = "https://api.checkfu.com/v1/blueprint-installations/apply"
payload = {
"files": {},
"available_references": [{ "name": "<string>" }],
"credentialed": ["<string>"],
"agent_blueprint_release_id": None,
"webhook_secret_inputs": [
{
"requirement": "<string>",
"value": "<string>"
}
]
}
headers = {
"checkfu-version": "<checkfu-version>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'checkfu-version': '<checkfu-version>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
files: {},
available_references: [{name: '<string>'}],
credentialed: ['<string>'],
agent_blueprint_release_id: null,
webhook_secret_inputs: [{requirement: '<string>', value: '<string>'}]
})
};
fetch('https://api.checkfu.com/v1/blueprint-installations/apply', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.checkfu.com/v1/blueprint-installations/apply",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'files' => [
],
'available_references' => [
[
'name' => '<string>'
]
],
'credentialed' => [
'<string>'
],
'agent_blueprint_release_id' => null,
'webhook_secret_inputs' => [
[
'requirement' => '<string>',
'value' => '<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"checkfu-version: <checkfu-version>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.checkfu.com/v1/blueprint-installations/apply"
payload := strings.NewReader("{\n \"files\": {},\n \"available_references\": [\n {\n \"name\": \"<string>\"\n }\n ],\n \"credentialed\": [\n \"<string>\"\n ],\n \"agent_blueprint_release_id\": null,\n \"webhook_secret_inputs\": [\n {\n \"requirement\": \"<string>\",\n \"value\": \"<string>\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("checkfu-version", "<checkfu-version>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.checkfu.com/v1/blueprint-installations/apply")
.header("checkfu-version", "<checkfu-version>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"files\": {},\n \"available_references\": [\n {\n \"name\": \"<string>\"\n }\n ],\n \"credentialed\": [\n \"<string>\"\n ],\n \"agent_blueprint_release_id\": null,\n \"webhook_secret_inputs\": [\n {\n \"requirement\": \"<string>\",\n \"value\": \"<string>\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.checkfu.com/v1/blueprint-installations/apply")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["checkfu-version"] = '<checkfu-version>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"files\": {},\n \"available_references\": [\n {\n \"name\": \"<string>\"\n }\n ],\n \"credentialed\": [\n \"<string>\"\n ],\n \"agent_blueprint_release_id\": null,\n \"webhook_secret_inputs\": [\n {\n \"requirement\": \"<string>\",\n \"value\": \"<string>\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"id": "<string>",
"workspace_id": "<string>",
"blueprint_name": "<string>",
"agent_blueprint_release_id": "<string>",
"applied_version": 1,
"release_hash": "<string>",
"lifecycle": "planned",
"resolved_resources": [
{
"resource_kind": "<string>",
"logical_name": "<string>",
"resource_id": "<string>",
"ownership": "created",
"config_hash": "<string>",
"management": "adopted",
"manage_mode": "reconcile"
}
],
"missing_inputs": [
"<string>"
],
"history": [
{
"operation_id": "<string>",
"kind": "plan",
"release_hash": "<string>",
"at": "<string>"
}
],
"version": 1,
"created_at": "<string>",
"updated_at": "<string>",
"provenance": "client_asserted"
}{
"error": {
"type": "validation.malformed",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-malformed"
}
}{
"error": {
"type": "auth.invalid_key",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-invalid-key"
}
}{
"error": {
"type": "auth.disabled_tenancy",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-disabled-tenancy"
}
}{
"error": {
"type": "validation.not_found",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-not-found"
}
}{
"error": {
"type": "validation.conflict",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-conflict"
}
}{
"error": {
"type": "budget.exceeded",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#budget-exceeded"
}
}{
"error": {
"type": "runtime.internal",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#runtime-internal"
}
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Headers
2026-08-24 255Body
- Option 1
- Option 2
Response
Success
^bins_[0-9a-f]{32}$^wrkspc_[0-9a-f]{32}$1 - 94^abrel_[0-9a-f]{32}$x > 0^sha256:[0-9a-f]{64}$planned, applied, upgraded, drifted, uninstalled Show child attributes
Show child attributes
Credential or human-input steps still owed before the install is complete.
1Show child attributes
Show child attributes
Optimistic-write token for the record itself.
x > 0client_asserted, reconciled