Section
Developer Platform
Build against your SaaS with the app-scoped Developer API, webhooks, connectors, AI, logs, MCP tools, the CLI, and secure installed services.
API MapEvery first-class and Build This route, with complete lifecycle and usability coverage.Choose your developer kit and versionDownload the current public kit, understand version numbers, or get a kit scoped to your tenant account.Developer platform overviewOne permission-aware developer surface for records, connectors, events, AI, logs, MCP, and installed services.Build a complete headless SaaSUse every promoted first-class module from your own React, mobile, desktop, or legacy interface without exposing an API credential to the browser.How customer organizations can signup from your websiteConnect your SaaS marketing-site signup and login to one governed BuildWithHQ customer organization and its first owner.Build This API recipesEighteen complete, contract-backed API slices for BuildWithHQ and API43 product concepts.Developer API quickstartCreate an app-scoped credential, verify its identity, make a first record request, and retain correlation evidence.REST APIsThe current resource-oriented v1 API for app identity, records, connectors, webhooks, AI, logs, contracts, and installed services.Authentication and API clientsUse isolated draft credentials for unpublished page JSON and an explicit live credential for publication and production operations.Requests, responses, errors, and correlation IDsThe conventions every client should apply for JSON, pagination, safe errors, retries, and operational evidence.Permission-aware data accessEvery data surface resolves through the same record, role, location, and capability envelope.Connectors, OAuth, and provider secretsDiscover supported connector types and configure data, payment, and OAuth connections without sending raw provider secrets.Inbound endpointsCreate app-bound inbound entry points, rotate keys, and process incoming events through authenticated application APIs.Webhooks and event deliveryPush signed application events to external systems with retries, idempotency, and observable delivery history.Webhook receiver and background-job polling examplesRun the exact-body webhook receiver and bounded AI rebuild poller published at webhooks.buildwithhq.com.Logs, diagnostics, and correlation tracingTail and search bounded app logs, then follow one correlation ID across related operational evidence.AI ingestion, rebuilds, and multimodal searchUse the secured tenant AI surface for authorized record ingestion, rebuild operations, and Qwen3-VL search.Database contract lock filesGenerate, diff, and verify safe schema signatures without exposing tables, stored procedures, DSNs, or database credentials.Workflows and custom actionsBuild durable server-side automations from native actions, approvals, waits, webhooks, AI actions, and extension services.MCP tools for AI clientsExpose approved API-backed application capabilities to MCP-compatible AI clients under the same permission envelope.Use BuildWithHQ with DeepSeek HarnessConnect DeepSeek Harness to the curated BuildWithHQ MCP surface with a tested Streamable HTTP patch, app or delegated-user identity, and exact tool-name mapping.Marketplace service API discoveryDiscover installed custom endpoint schemas, download per-app OpenAPI, and let MCP agents plan governed calls.Extensible container servicesAdd custom code in an isolated container, then expose it through declared endpoints the BuildWithHQ runtime can safely invoke.BuildWithHQ CLIUse the shipped .NET 10 CLI for profiles, app delivery, templates, services, API clients, workers, AI, logs, and contract locks.OpenAPI, versioning, and SDKsKeep the API reference, schemas, generated clients, and changelog synchronized from one canonical contract.Pagination, filtering, rate limits, and versioningImplement list traversal, server-side filters, 429 recovery, and contract pinning from the exact OpenAPI operation.Limits, rate limits, and idempotencyHow clients should handle quotas, throttling, payload boundaries, retries, and safely repeated writes.Integration go-live checklistA practical review for credentials, scopes, retries, webhooks, observability, test isolation, and operational ownership.