Skip to content

Campus public platform API

This file is generated from crates/campus-sdk/platform_operations.json. The registry is the review boundary for stable developer-facing Campus primitives. Product-owned contracts remain in MCP and are intentionally absent.

OperationCampusSDK facadePlaneAuthorityConfirmationMeaning
access.grantcampus.access.grantserviceinstallationnoneAuthorize a Campus user for this app.
access.listcampus.access.listserviceinstallationnoneList users authorized for this app.
access.revokecampus.access.revokeserviceinstallationnoneRevoke a user's access to this app.
account.currentcampus.account.currentshellaccount.profile.read:*noneRead the current public account identity.
account.identitycampus.account.identityserviceinstallationnoneRead the authenticated account identity bound to this installation.
activity.snapshotcampus.activity.snapshotservicecommerce.campus.read:*noneRead this account's runtime activity and Campus billing history.
apps.createcampus.apps.createshellapps.create:selftrusted-shellCreate a user-owned application workspace.
apps.forkcampus.apps.forkshellapps.create:target-apptrusted-shellFork an app interface into a user-owned workspace.
apps.getcampus.apps.getshellapps.catalog.read:*noneResolve an app by ID or name.
apps.installcampus.apps.installshellapps.install:target-apptrusted-shellInstall an app with reviewed grants.
apps.listcampus.apps.listshellapps.catalog.read:*noneList apps visible to this account.
apps.opencampus.apps.openshellapps.lifecycle:target-appnoneOpen an installed app.
apps.pausecampus.apps.pauseshellapps.lifecycle:target-appnonePause an installed workload.
apps.purchasecampus.apps.purchaseshellapps.install:target-appfinancial-intentPurchase and install a Store app through the trusted payment flow.
apps.searchcampus.apps.searchshellapps.catalog.read:*noneSearch the public app catalog.
apps.startcampus.apps.startshellapps.lifecycle:target-appnoneStart an installed workload.
apps.stopcampus.apps.stopshellapps.lifecycle:target-appnoneStop an installed workload.
apps.uninstallcampus.apps.uninstallshellapps.uninstall:target-apptrusted-shellUninstall an app while preserving data unless explicitly deleted.
apps.warmcampus.apps.warmshellapps.lifecycle:target-appnoneWarm an installed workload.
backend.acquireLeasecampus.backend.acquireLeaseserviceinstallationnoneKeep admitted workload work alive for a bounded duration.
backend.fetchcampus.backend.fetchworkloadinstallationnoneCall this installation's private workload.
backend.openEventStreamcampus.backend.openEventStreamworkloadinstallationnoneOpen a private workload event stream.
backend.openSocketcampus.backend.openSocketworkloadinstallationnoneOpen a private workload WebSocket.
crypto.keycampus.crypto.keyshellkeyring.namespaces.use:namespacenoneOpen a scoped browser key handle.
deliveries.acknowledgecampus.deliveries.acknowledgeservicedeliveries.receive:channelnoneAcknowledge one addressed opaque envelope.
deliveries.cancelcampus.deliveries.cancelservicedeliveries.send:recipient-app:channelnoneCancel one pending addressed opaque envelope.
deliveries.getcampus.deliveries.getservicedeliveries.receive:channelnoneOpen one addressed opaque envelope for this exact installation.
deliveries.listcampus.deliveries.listservicedeliveries.receive:channelnoneList addressed opaque envelopes for this exact installation.
deliveries.sendcampus.deliveries.sendservicedeliveries.send:recipient-app:channelnoneSend a bounded opaque envelope to an exact account and app recipient.
distribution.publishcampus.distribution.publishservicecommerce.products.manage:*trusted-shellBuild, package, price, and publish an immutable app release.
distribution.publishReleasecampus.distribution.publishReleaseservicecommerce.products.manage:*trusted-shellBuild and publish the next immutable release of an existing app product.
distribution.sourcescampus.distribution.sourcesservicecommerce.products.manage:*noneList user-owned apps eligible for distribution.
distribution.withdrawcampus.distribution.withdrawservicecommerce.products.manage:*trusted-shellWithdraw a product from new Store purchases without breaking installations.
domains.attachDnscampus.domains.attachDnsservicepublic-domains.manage:*noneRecord the provider DNS identity for a public domain binding.
domains.bindcampus.domains.bindservicepublic-domains.manage:*noneBind an external hostname to an app with an approved public route.
domains.finalizecampus.domains.finalizeservicepublic-domains.manage:*noneFinalize removal after provider DNS cleanup.
domains.refreshcampus.domains.refreshservicepublic-domains.manage:*noneRefresh provider and TLS status for a public domain binding.
domains.snapshotcampus.domains.snapshotservicepublic-domains.manage:*noneList account-owned public domain bindings and provider status.
domains.unbindcampus.domains.unbindservicepublic-domains.manage:*noneBegin removing an account-owned public domain binding.
files.createcampus.files.createservicefiles.user.manage:selfnoneCreate a logical user file.
files.listcampus.files.listservicefiles.user.manage:selfnoneList logical user files.
files.readcampus.files.readservicefiles.user.manage:selfnoneRead an authorized logical user file.
files.writecampus.files.writeservicefiles.user.manage:selfnoneWrite an authorized logical user file.
intelligence.requestcampus.intelligence.requestserviceintelligence.use:modelnoneRun inference within the installation's model and budget grants.
kvcampus.kvshellapp-data.sync:namespacenoneOpen isolated synchronized key-value storage.
mcp.callcampus.mcp.callservicemcp.tools.call:qualified-toolcontractCall a permission-filtered Campus MCP tool.
mcp.serveBrowsercampus.mcp.serveBrowsershellmcp.tools.serve:owner-toolnoneServe an approved browser-owned MCP tool.
notifications.listcampus.notifications.listservicenotifications.read:topicnoneList authorized account notifications.
notifications.publishcampus.notifications.publishservicenotifications.publish:topicnonePublish an account notification on an authorized topic.
payments.proposecampus.payments.proposeshellwallet.payment.propose:addressfinancial-intentPropose one exact payment for trusted approval.
permissions.requestcampus.permissions.requestshellinstallationtrusted-shellRequest a bounded change to this installation's grants.
permissions.revokecampus.permissions.revokeshellinstallationtrusted-shellRevoke one of this installation's grants.
readycampus.readyshellinstallationnoneReport that the app interface is ready.
rendezvous.closecampus.rendezvous.closeservicerendezvous.use:namespacenoneClose a coordination session for both admitted peers.
rendezvous.createcampus.rendezvous.createservicerendezvous.use:namespacenoneCreate a TTL-bound coordination session with an exact account and app peer.
rendezvous.getcampus.rendezvous.getservicerendezvous.use:namespacenoneRead one admitted TTL-bound coordination session.
rendezvous.listcampus.rendezvous.listservicerendezvous.use:namespacenoneList TTL-bound coordination sessions for this exact installation.
rendezvous.messagescampus.rendezvous.messagesservicerendezvous.use:namespacenoneRead ordered opaque frames from a coordination session.
rendezvous.sendcampus.rendezvous.sendservicerendezvous.use:namespacenoneAppend one bounded opaque frame to a coordination session.
schedules.createcampus.schedules.createshellschedules.manage:*trusted-shellCreate a schedule for an eligible app tool.
search.indexcampus.search.indexservicesearch.index:selfnoneReplace this app's private search entries.
search.querycampus.search.queryshellsearch.query:*noneQuery the account search index.
settings.snapshotcampus.settings.snapshotshellsettings.account-uinoneRead account settings from a nondelegable settings surface.
shell.dismisscampus.shell.dismissshellinstallationnoneDismiss the current bounded app surface.
speech.startcampus.speech.startshellmedia.transcription.use:selfbrowser-permissionStart microphone transcription in the visible app surface.

Software belongs to people. Campus gives it a durable place to run.