One space's placements, and what the caller could still place there
Accessible to readers of the target space. Every row carries its placements, narrowed to this space: a package homed here, offered here, or shipped with the platform, with state saying whether the space runs it — none is exactly a pending offer, taken up with POST /api/spaces/{spaceId}/packages like any other activation. The rows also include what the caller could still PLACE here, so the listing never proposes a package that door would refuse: for a TEAM destination, a package whose home grants them the type's share permission (home_shareable, since activating then creates the offer); for a PERSONAL destination, nothing beyond what is already placed — an offer into somebody's own space is somebody else's act. Such a candidate carries an EMPTY placements array. Each package type requires read permission in the target space. Activation remains subject to the target space's permissions, waived in the caller's own personal space. Personal spaces remain private and API keys remain pinned to their space.
/api/spaces/{spaceId}/libraryCookie session from Better Auth. Requires X-Org-Id header for org-scoped routes.
In: cookie
Path Parameters
Header Parameters
Organization ID. Required for cookie auth. Not needed for API key auth (org resolved from key).
uuidcurl -X GET "https://your-instance/api/spaces/string/library"{
"object": "library",
"spaces": [
{
"id": "spc_3e6f8a1b-2c4d-4e70-8f92-a1b3c5d7e9f0",
"name": "Default",
"isDefault": true
},
{
"id": "spc_7f0a2c4e-6b81-4d3f-9e57-c2a4b6d8e0f1",
"name": "Staging",
"isDefault": false
}
],
"packages": {
"agent": [
{
"id": "pkg_inbox_triage",
"type": "agent",
"source": "local",
"name": "Inbox Triage",
"description": "Sorts incoming Gmail threads into priority buckets.",
"home_space_id": "spc_3e6f8a1b-2c4d-4e70-8f92-a1b3c5d7e9f0",
"home_writable": true,
"home_deletable": true,
"home_shareable": true,
"published": true,
"placements": [
{
"space_id": "spc_3e6f8a1b-2c4d-4e70-8f92-a1b3c5d7e9f0",
"via": "home",
"state": "active",
"chat_enforced": false,
"shared_by": null
},
{
"space_id": "spc_7f0a2c4e-6b81-4d3f-9e57-c2a4b6d8e0f1",
"via": "shared",
"state": "none",
"chat_enforced": false,
"shared_by": {
"user_id": "usr_1",
"name": "Alex"
}
}
]
}
],
"skill": [],
"mcp-server": [],
"integration": [
{
"id": "pkg_gmail",
"type": "integration",
"source": "system",
"name": "Gmail",
"description": "Google Mail OAuth integration.",
"home_space_id": null,
"home_writable": false,
"home_deletable": false,
"home_shareable": false,
"published": true,
"placements": [
{
"space_id": "spc_3e6f8a1b-2c4d-4e70-8f92-a1b3c5d7e9f0",
"via": "system",
"state": "active",
"chat_enforced": false,
"shared_by": null
},
{
"space_id": "spc_7f0a2c4e-6b81-4d3f-9e57-c2a4b6d8e0f1",
"via": "system",
"state": "inactive",
"chat_enforced": false,
"shared_by": null
}
]
}
]
}
}{
"type": "https://docs.appstrate.dev/errors/unauthorized",
"title": "Unauthorized",
"status": 401,
"detail": "Invalid or missing session",
"code": "unauthorized",
"request_id": "req_abc123"
}{
"type": "https://docs.appstrate.dev/errors/forbidden",
"title": "Forbidden",
"status": 403,
"detail": "Insufficient permissions",
"code": "forbidden",
"request_id": "req_abc123"
}{
"type": "https://docs.appstrate.dev/errors/not-found",
"title": "Not Found",
"status": 404,
"detail": "Resource not found",
"code": "not_found",
"request_id": "req_abc123"
}