> ## Documentation Index
> Fetch the complete documentation index at: https://checkfu.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Apply an AgentBlueprint package

> Reconcile an immutable published AgentBlueprint package, or the dated inline-package compatibility request, into ordinary governed aggregates. Live Workspace authority resolves every reference and custody requirement. Automation-bound webhook SecretRequirements are supplied through the bounded, write-only webhook_secret_inputs sidecar for creation and managed secret rotation; an unchanged reapply may omit the sidecar, while a changed webhook declaration must supply its exact named requirement. Values are routed only to ordinary Automation create or patch operations and never appear in the package, plan, installation, or response. Returns the resulting BlueprintInstallation with created-versus-reused ownership and any still-owed inputs; accepts an optional Idempotency-Key.

Checkfu support posture: alpha; hosted. Required evidence journey: blueprint-authority. Deployment-specific readiness and the latest proven release are available from GET /v1/support/capabilities.



## OpenAPI

````yaml /openapi.json post /v1/blueprint-installations/apply
openapi: 3.1.0
info:
  title: Checkfu API
  version: '2026-08-27'
  description: >-
    Authentication is declared per operation: API-key, runtime, or connector
    bearer; Automation signature; or credential-free pairing redemption. Every
    general Checkfu REST request requires the dated `Checkfu-Version` header
    (one of: 2026-08-27); the three MCP JSON-RPC transports use
    `MCP-Protocol-Version`, A2A uses `A2A-Version`, and the provider OAuth
    callback carries neither Checkfu header. API keys resolve one Workspace
    without a request selector; authenticated responses identify it with
    `Checkfu-Workspace-Id`.
servers:
  - url: https://api.checkfu.com
security:
  - bearerAuth: []
tags:
  - name: organizations
  - name: sourceRepositories
  - name: tenants
  - name: workspaces
  - name: principals
  - name: principalGroups
  - name: principalAccessCredentials
  - name: apiKeys
  - name: agents
  - name: harnesses
  - name: harnessRuntime
  - name: sandboxProfiles
  - name: computerProfiles
  - name: permissionAssignments
  - name: actionPolicies
  - name: files
  - name: memoryStores
  - name: dreams
  - name: modelCredentials
  - name: modelRoutingProfiles
  - name: blueprintInstallations
  - name: toolSources
  - name: skills
  - name: skillSources
  - name: agentSources
  - name: skillProposals
  - name: instructionProposals
  - name: catalog
  - name: concepts
  - name: support
  - name: connections
  - name: connectionVaults
  - name: connectionAssignments
  - name: connectedRuntimes
  - name: projects
  - name: collaboration
  - name: automationGraphs
  - name: automations
  - name: actionApprovals
  - name: standingApprovals
  - name: usage
  - name: models
  - name: outcomes
  - name: budgets
  - name: billing
  - name: sessions
  - name: audit
  - name: sessionExports
  - name: runs
  - name: runnerPools
  - name: transcripts
  - name: sessionWatches
  - name: webhookEndpoints
  - name: integrationGateway
  - name: agentDeployments
  - name: workEnvironments
  - name: computers
  - name: computerScreens
  - name: computerBrowserObservations
  - name: computerBrowserActions
  - name: environments
  - name: vaults
  - name: apiMcp
  - name: a2a
paths:
  /v1/blueprint-installations/apply:
    post:
      tags:
        - blueprintInstallations
      summary: Apply an AgentBlueprint package
      description: >-
        Reconcile an immutable published AgentBlueprint package, or the dated
        inline-package compatibility request, into ordinary governed aggregates.
        Live Workspace authority resolves every reference and custody
        requirement. Automation-bound webhook SecretRequirements are supplied
        through the bounded, write-only webhook_secret_inputs sidecar for
        creation and managed secret rotation; an unchanged reapply may omit the
        sidecar, while a changed webhook declaration must supply its exact named
        requirement. Values are routed only to ordinary Automation create or
        patch operations and never appear in the package, plan, installation, or
        response. Returns the resulting BlueprintInstallation with
        created-versus-reused ownership and any still-owed inputs; accepts an
        optional Idempotency-Key.


        Checkfu support posture: alpha; hosted. Required evidence journey:
        blueprint-authority. Deployment-specific readiness and the latest proven
        release are available from GET /v1/support/capabilities.
      operationId: blueprintInstallations.applyBlueprint
      parameters:
        - name: checkfu-version
          in: header
          schema:
            type: string
            enum:
              - '2026-08-27'
          required: true
        - name: idempotency-key
          in: header
          schema:
            type: string
            allOf:
              - maxLength: 255
          required: false
      requestBody:
        content:
          application/json:
            schema:
              anyOf:
                - type: object
                  properties:
                    agent_blueprint_release_id:
                      type: 'null'
                    files:
                      type: object
                      additionalProperties:
                        type: string
                      description: >-
                        Blueprint directory as relative-path → UTF-8 file
                        content.
                    available_references:
                      type: array
                      items:
                        type: object
                        properties:
                          kind:
                            $ref: '#/components/schemas/Union_136'
                          name:
                            type: string
                        required:
                          - kind
                          - name
                        additionalProperties: false
                    credentialed:
                      type: array
                      items:
                        type: string
                    webhook_secret_inputs:
                      $ref: '#/components/schemas/UniqueBlueprintWebhookSecretInputs'
                  required:
                    - files
                    - available_references
                    - credentialed
                  additionalProperties: false
                - type: object
                  properties:
                    files:
                      type: 'null'
                    agent_blueprint_release_id:
                      $ref: '#/components/schemas/AgentBlueprintReleaseId'
                    available_references:
                      description: >-
                        Compatibility hint only; the server resolves
                        package-declared references from live Workspace
                        authority.
                      anyOf:
                        - type: array
                          items:
                            type: object
                            properties:
                              kind:
                                $ref: '#/components/schemas/Union_136'
                              name:
                                type: string
                            required:
                              - kind
                              - name
                            additionalProperties: false
                    credentialed:
                      description: >-
                        Compatibility hint only; exact server-side custody
                        authority is required and unsupported slot selectors
                        fail closed.
                      anyOf:
                        - type: array
                          items:
                            type: string
                    webhook_secret_inputs:
                      description: >-
                        Transient write-only values for Automation-bound secret
                        requirements during creation or managed rotation; never
                        persisted in the package, plan, installation, or
                        response.
                      anyOf:
                        - $ref: >-
                            #/components/schemas/UniqueBlueprintWebhookSecretInputs
                  required:
                    - agent_blueprint_release_id
                  additionalProperties: false
        required: true
      responses:
        '201':
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    $ref: '#/components/schemas/BlueprintInstallationId'
                  workspace_id:
                    $ref: '#/components/schemas/WorkspaceId'
                  blueprint_name:
                    type: string
                    allOf:
                      - minLength: 1
                      - maxLength: 94
                  agent_blueprint_release_id:
                    $ref: '#/components/schemas/Union_137'
                  applied_version:
                    type: integer
                    allOf:
                      - exclusiveMinimum: 0
                  release_hash:
                    type: string
                    allOf:
                      - pattern: ^sha256:[0-9a-f]{64}$
                  lifecycle:
                    $ref: '#/components/schemas/Union_138'
                  resolved_resources:
                    $ref: '#/components/schemas/Arrays_26'
                  missing_inputs:
                    $ref: '#/components/schemas/Arrays_27'
                  history:
                    $ref: '#/components/schemas/Arrays_28'
                  provenance:
                    type: string
                    enum:
                      - client_asserted
                      - reconciled
                  version:
                    type: integer
                    allOf:
                      - exclusiveMinimum: 0
                        description: Optimistic-write token for the record itself.
                  created_at:
                    type: string
                  updated_at:
                    type: string
                required:
                  - id
                  - workspace_id
                  - blueprint_name
                  - agent_blueprint_release_id
                  - applied_version
                  - release_hash
                  - lifecycle
                  - resolved_resources
                  - missing_inputs
                  - history
                  - version
                  - created_at
                  - updated_at
                additionalProperties: false
          headers:
            checkfu-workspace-id:
              description: The Workspace resolved from the authenticated bearer credential.
              required: true
              schema:
                $ref: '#/components/schemas/WorkspaceId'
        '400':
          description: Typed Checkfu wire error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationMalformedError'
        '401':
          description: Typed Checkfu wire error
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                properties:
                  error:
                    type: object
                    required:
                      - type
                      - message
                      - more
                    properties:
                      type:
                        type: string
                        enum:
                          - auth.invalid_key
                      message:
                        type: string
                      more:
                        type: string
                        enum:
                          - >-
                            https://docs.checkfu.com/reference/errors#auth-invalid-key
                        description: >-
                          Stable public documentation and remedy for this error
                          type.
                    additionalProperties: false
                additionalProperties: false
        '403':
          description: >-
            The organization, tenant, or workspace backing this key is
            administratively disabled. | Deployment governance or retention
            policy denied the request.
          content:
            application/json:
              schema:
                anyOf:
                  - type: object
                    required:
                      - error
                    properties:
                      error:
                        type: object
                        properties:
                          type:
                            type: string
                            enum:
                              - auth.disabled_tenancy
                          message:
                            type: string
                          more:
                            type: string
                            enum:
                              - >-
                                https://docs.checkfu.com/reference/errors#auth-disabled-tenancy
                            description: >-
                              Stable public documentation and remedy for this
                              error type.
                        required:
                          - type
                          - message
                          - more
                        additionalProperties: false
                    additionalProperties: false
                  - $ref: '#/components/schemas/PolicyDeniedError'
        '404':
          description: >-
            The requested resource does not exist in the resolved deployment
            boundary.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationNotFoundError'
        '409':
          description: >-
            The request conflicts with the resource's current state. | An
            idempotent mutation conflicts with a completed or in-progress
            request for the same key.
          content:
            application/json:
              schema:
                anyOf:
                  - $ref: '#/components/schemas/ValidationConflictError'
                  - $ref: '#/components/schemas/IdempotencyConflictError'
        '429':
          description: Typed Checkfu wire error
          headers:
            retry-after:
              description: >-
                Delay in seconds for rate limits or deployment quotas with a
                known release or UTC reset boundary
              required: false
              schema:
                type: integer
                minimum: 1
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                properties:
                  error:
                    type: object
                    required:
                      - type
                      - message
                      - more
                    properties:
                      type:
                        type: string
                        enum:
                          - budget.exceeded
                      message:
                        type: string
                      more:
                        type: string
                        enum:
                          - >-
                            https://docs.checkfu.com/reference/errors#budget-exceeded
                        description: >-
                          Stable public documentation and remedy for this error
                          type.
                    additionalProperties: false
                additionalProperties: false
        '500':
          description: >-
            An unexpected internal failure occurred; the message contains an
            opaque incident reference.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RuntimeInternalError'
      security:
        - bearerAuth: []
components:
  schemas:
    Union_136:
      type: string
      enum:
        - principal
        - model_routing_profile
        - sandbox_profile
        - external_installation
        - surface_scope
        - connection
        - memory_store
        - budget
        - policy
        - permission_assignment
        - automation
        - agent_definition
        - blueprint_installation
    UniqueBlueprintWebhookSecretInputs:
      type: array
      items:
        type: object
        properties:
          requirement:
            type: string
            allOf:
              - pattern: ^[a-z0-9](?:[a-z0-9._-]{0,93})$
          value:
            type: string
            allOf:
              - pattern: ^whsec_[A-Za-z0-9_-]{43}$
        required:
          - requirement
          - value
        additionalProperties: false
      allOf:
        - maxItems: 16
    AgentBlueprintReleaseId:
      type: string
      allOf:
        - pattern: ^abrel_[0-9a-f]{32}$
    BlueprintInstallationId:
      type: string
      allOf:
        - pattern: ^bins_[0-9a-f]{32}$
    WorkspaceId:
      type: string
      allOf:
        - pattern: ^wrkspc_[0-9a-f]{32}$
    Union_137:
      anyOf:
        - $ref: '#/components/schemas/AgentBlueprintReleaseId_1'
        - type: 'null'
    Union_138:
      type: string
      enum:
        - planned
        - applied
        - upgraded
        - drifted
        - uninstalled
    Arrays_26:
      type: array
      items:
        type: object
        properties:
          resource_kind:
            type: string
            allOf:
              - minLength: 1
          logical_name:
            type: string
            allOf:
              - minLength: 1
          resource_id:
            anyOf:
              - type: string
                allOf:
                  - minLength: 1
              - type: 'null'
          ownership:
            type: string
            enum:
              - created
              - reused
          management:
            type: string
            enum:
              - adopted
          manage_mode:
            type: string
            enum:
              - reconcile
              - replace
              - none
          config_hash:
            anyOf:
              - type: string
                allOf:
                  - minLength: 1
              - type: 'null'
        required:
          - resource_kind
          - logical_name
          - resource_id
          - ownership
          - config_hash
        additionalProperties: false
    Arrays_27:
      type: array
      items:
        type: string
        allOf:
          - minLength: 1
      description: >-
        Credential or human-input steps still owed before the install is
        complete.
    Arrays_28:
      type: array
      items:
        type: object
        properties:
          operation_id:
            type: string
            allOf:
              - minLength: 1
          kind:
            type: string
            enum:
              - plan
              - apply
              - upgrade
              - rollback
              - uninstall
          release_hash:
            type: string
            allOf:
              - pattern: ^sha256:[0-9a-f]{64}$
          at:
            type: string
        required:
          - operation_id
          - kind
          - release_hash
          - at
        additionalProperties: false
    ValidationMalformedError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - validation.malformed
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#validation-malformed
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        The request could not be decoded or violated a declared input
        constraint.
    PolicyDeniedError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - policy.denied
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#policy-denied
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: Deployment governance or retention policy denied the request.
    ValidationNotFoundError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - validation.not_found
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#validation-not-found
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        The requested resource does not exist in the resolved deployment
        boundary.
    ValidationConflictError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - validation.conflict
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#validation-conflict
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: The request conflicts with the resource's current state.
    IdempotencyConflictError:
      anyOf:
        - $ref: '#/components/schemas/ValidationIdempotencyConflictError'
        - $ref: '#/components/schemas/ValidationIdempotencyInProgressError'
      description: >-
        An idempotent mutation conflicts with a completed or in-progress request
        for the same key.
    RuntimeInternalError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - runtime.internal
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#runtime-internal
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        An unexpected internal failure occurred; the message contains an opaque
        incident reference.
    AgentBlueprintReleaseId_1:
      type: string
      allOf:
        - pattern: ^abrel_[0-9a-f]{32}$
    ValidationIdempotencyConflictError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - validation.idempotency_conflict
            message:
              type: string
            more:
              type: string
              enum:
                - >-
                  https://docs.checkfu.com/reference/errors#validation-idempotency-conflict
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: The Idempotency-Key is already bound to a different request.
    ValidationIdempotencyInProgressError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - validation.idempotency_in_progress
            message:
              type: string
            more:
              type: string
              enum:
                - >-
                  https://docs.checkfu.com/reference/errors#validation-idempotency-in-progress
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        An identical idempotent request is still in progress and may be retried
        later.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer

````