Restore an MCP-server package version into the draft

Restore a previously published version into the MCP-server package draft. Does not create a new version. Authority is the package's HOME space (packages.home_space_id, RBAC spec §6.9): this route requires the package type's write (delete for a delete) THERE and nowhere else — not in the space the request is made from, which merely consumes a placement and has no say over the draft, the versions or the identity. Every package of the organization has a home; one that belongs to no team is homed in the organization's default space, which owners and admins reach like any other. An id the caller cannot READ at all answers 404 rather than 403, so this is not an existence oracle. Move the home with PUT /api/packages/{scope}/{name}/home.

POST/api/packages/mcp-servers/{scope}/{name}/versions/{version}/restore

Authorization

better-auth.session_token<token>

Cookie session from Better Auth. Requires X-Org-Id header for org-scoped routes.

In: cookie

Path Parameters

scope*string

Package scope (e.g. @myorg)

Match^@[a-z0-9][a-z0-9-]*$
name*string

Package name

version*string

Version to restore (exact, dist-tag, or semver range)

Header Parameters

X-Org-Id?string

Organization ID. Required for cookie auth. Not needed for API key auth (org resolved from key).

Formatuuid
X-Space-Id?string

Space ID. Required for space-scoped routes (agents, runs, schedules, and space-scoped module routes). Not needed for API key auth (space resolved from key).

If-Match?string

Optional optimistic-concurrency precondition (RFC 9110 §13.1.1): the ETag of the representation the write is based on. When it no longer matches the current version the write is refused with 412 precondition_failed and nothing changes. Omitted: last write wins.

curl -X POST "https://your-instance/api/packages/mcp-servers/string/string/versions/string/restore"
{
  "id": "string",
  "orgId": "string",
  "name": "string",
  "description": "string",
  "definition": "draft",
  "content": "string",
  "source": "local",
  "created_by": "string",
  "auto_installed": true,
  "version": "string",
  "manifest": {},
  "manifest_name": "string",
  "version_count": 0,
  "has_unarchived_changes": true,
  "forked_from": "string",
  "home_space_id": "string",
  "home_writable": true,
  "home_deletable": true,
  "home_shareable": true,
  "agents": [
    {
      "id": "string",
      "display_name": "string"
    }
  ],
  "createdAt": "2019-08-24T14:15:22Z",
  "updatedAt": "2019-08-24T14:15:22Z"
}
{
  "type": "https://docs.appstrate.dev/errors/unauthorized",
  "title": "Unauthorized",
  "status": 401,
  "detail": "Invalid or missing session",
  "code": "unauthorized",
  "request_id": "req_abc123"
}
{
  "type": "https://docs.appstrate.dev/errors/forbidden",
  "title": "Forbidden",
  "status": 403,
  "detail": "Insufficient permissions",
  "code": "forbidden",
  "request_id": "req_abc123"
}
{
  "type": "https://docs.appstrate.dev/errors/not-found",
  "title": "Not Found",
  "status": 404,
  "detail": "Resource not found",
  "code": "not_found",
  "request_id": "req_abc123"
}
{
  "type": "https://docs.appstrate.dev/errors/precondition-failed",
  "title": "Precondition Failed",
  "status": 412,
  "detail": "The resource changed since you read it: If-Match does not match its current ETag. Re-read it, reapply your change, and send the new ETag.",
  "code": "precondition_failed",
  "request_id": "req_abc123"
}
{
  "type": "http://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "instance": "string",
  "code": "string",
  "request_id": "string",
  "param": "string",
  "retry_after": 0,
  "errors": [
    {
      "field": "string",
      "code": "string",
      "message": "string",
      "title": "string",
      "candidate_connections": [
        {
          "id": "string",
          "label": "string",
          "account_id": "string",
          "owned_by_actor": true,
          "needs_reconnection": true
        }
      ],
      "connection_id": "string",
      "missing_scopes": [
        "string"
      ],
      "owned_by_actor": true,
      "required_scopes": [
        "string"
      ],
      "auth_key": "string",
      "required_auth_key": "string",
      "available_auth_keys": [
        "string"
      ],
      "connect_url": "http://example.com",
      "expiresAt": "2019-08-24T14:15:22Z",
      "packageId": "string"
    }
  ]
}