Skip to main content

Create Application

Creates a new application with optional parameters including description, logo, and privacy settings.

Endpoint​

POST /app/create

Authentication​

HeaderValue
AuthorizationBearer <jwt_token>

Request Body​

The request uses multipart/form-data format with the following fields:

FieldTypeRequiredDescription
appstring✅The name of the application to be created
filefile❌Logo of the application
descriptionstring❌App description
privateboolean❌Lock app (if selected, the app will be stored in a private bucket and cannot be changed)
download_modestring❌Private apps only: unlisted or strict, who may download artifacts and check for updates. Defaults to unlisted when ENABLE_PRIVATE_APP_DOWNLOADING=true, otherwise strict
tufboolean❌Enable TUF framework for application
cdnboolean❌Enable or disable API response caching on S3. Not allowed for private apps

Example Request​

cURL​

curl --location 'http://localhost:9000/app/create' \
--header 'Authorization: Bearer <jwt_token>' \
--form 'data="{\"app\":\"appName\", \"cdn\": \"true\"}"'

Private app​

curl --location 'http://localhost:9000/app/create' \
--header 'Authorization: Bearer <jwt_token>' \
--form 'data="{\"app\":\"appName\", \"private\": \"true\", \"download_mode\": \"strict\"}"'

Response​

Success Response (200 OK)​

{
"createAppResult.Created": "641459ffb8760d74164e7e3c"
}

Response Fields​

FieldTypeDescription
createAppResult.CreatedstringThe unique identifier (ID) of the created application

Notes​

  • The private field is irreversible - once set to true, the app cannot be made public later
  • The file field accepts common image formats (PNG, JPG, etc.)
  • The description field is optional but recommended for better app management
  • When cdn is set to true, API responses are cached on S3; set cdn to false to disable caching
  • private together with cdn: true is rejected with 400: CDN responses are public and would expose the private app's versions and links
  • An invalid download_mode is rejected with 400; for a public app the field is ignored
  • A private app supports only the manual, tauri and squirrel_darwin updaters. Feed-based updaters (velopack, sparkle, electron-builder, squirrel_windows) are rejected on upload
  • Clients of a strict app need a download token for update checks and downloads