Authentication and tenant boundary
Both endpoints requiresession:read:
- A server integration sends its organization-scoped OAO API key as
Authorization: Bearer $OAO_API_KEY. The project in the URL must belong to that key’s organization. - A signed-in Console user is authorized through the normal HTTP-only browser session and must resolve to the requested project.
List files
data: [] and null for the
three backup fields.
Download a file
path returned by the list endpoint. Encode every path segment
independently while preserving / separators.
application/octet-stream and includes
Content-Disposition: attachment, Content-Length, Cache-Control: no-store,
and X-Content-Type-Options: nosniff.
JavaScript SDK
Shared workspaces and integrity
Delegated child sessions resolve through the coordinator’s shared workspace, so the same persistent backup is available through either session ID when the caller is authorized. Before sending bytes, OAO verifies the manifest binding, archive length, SHA-256 digest, tar structure, entry type, and declared file size. Extraction is streamed without writing the requested file to the API host filesystem. The current API exposes only the latest successful backup generation. It does not provide historical generations, directory downloads, or byte ranges.Errors
See Authentication for API-key creation and
cross-project organization behavior, and Send files to an agent
for the separate upload contract.

