REST API
Read tokens and releases, propose changes and manage themes and webhooks over HTTPS. Every call runs as the key's owner, inside their roles.
Authentication
Create a key in Settings > API keys and send it as a bearer token. Keys act as you; revoke them at any time.
curl -H "Authorization: Bearer $STOAKEN_API_KEY" https://stoaken.com/api/brandsVersions
Pin a version with the Stoaken-Version header (current: 2026-09-29). Responses echo the version they used.
Rate limits
120 requests per minute per key, and 60 writes per hour. Every response carries RateLimit-Limit, RateLimit-Remaining and RateLimit-Reset; over the limit you get 429 with Retry-After.
Idempotency
Send an Idempotency-Key header on writes. Repeating the same request with the same key returns the first response (with Idempotent-Replayed: true) instead of doing it twice.
Errors
Errors are RFC 9457 problem documents (application/problem+json) with a type you can look up at /api/problems/<slug> and a plain detail. On the Free plan, writes return 403 with what to upgrade.
Endpoints
The full schema is at /api/openapi.json (OpenAPI 3.1). Lists are paginated with limit and cursor.
| Method | Path | Kind |
|---|---|---|
GET | /api/brands | Read |
GET | /api/brands/:brandId | Read |
GET | /api/brands/:brandId/token-sets | Read |
GET | /api/brands/:brandId/themes | Read |
POST | /api/brands/:brandId/themes | Write |
GET | /api/token-sets/:tokenSetId | Read |
PUT | /api/token-sets/:tokenSetId/document | Write |
PATCH | /api/token-sets/:tokenSetId/tokens | Write |
GET | /api/themes/:themeId | Read |
PATCH | /api/themes/:themeId | Write |
DELETE | /api/themes/:themeId | Write |
GET | /api/themes/:themeId/tokens | Read |
GET | /api/themes/:themeId/tokens/raw | Read |
GET | /api/themes/:themeId/deprecations | Read |
POST | /api/themes/:themeId/deprecations | Write |
GET | /api/themes/:themeId/releases | Read |
GET | /api/themes/:themeId/export | Read |
POST | /api/themes/:themeId/releases | Write |
GET | /api/releases/:releaseId | Read |
GET | /api/releases/:releaseId/snapshot | Read |
GET | /api/releases/:releaseId/export | Read |
POST | /api/releases/:releaseId/submit | Write |
GET | /api/brands/:brandId/webhooks | Read |
POST | /api/brands/:brandId/webhooks | Write |
PATCH | /api/webhooks/:webhookId | Write |
DELETE | /api/webhooks/:webhookId | Write |
POST | /api/webhooks/:webhookId/rotate-secret | Write |
POST | /api/webhooks/:webhookId/ping | Write |
curl -X POST https://stoaken.com/api/themes/$THEME_ID/releases \
-H "Authorization: Bearer $STOAKEN_API_KEY" \
-H "Idempotency-Key: release-1-4-0" \
-H "Content-Type: application/json" \
-d '{"version":"1.4.0"}'