A general API with personal access tokens and scopes, beyond the capture API #12
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Blocks
Reference
Postulo/postulo#12
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why this exists
postulo-mcp (#19) needs to read and change a person's job hunt on their behalf. The browser extensions (#17, #18) will want to ask "is this posting already tracked?" and show the answer. The capture API is designed to be unable to do any of that — the docstring of
api/api.pyand the wiki page The capture API both promise it: cannot read, cannot change, cannot sign in. That design is right for a token that lives in a browser profile. It does not stretch to an agent.What exists today
NinjaAPIat/api/v1with three routes:GET /me,POST /captures,GET /captures.docs_url=None, so there is no OpenAPI page.CaptureToken(api/models.py): hashed at rest, shown once, a prefix for identification, last-used, revocable. Its docstring says the scope is not configurable "because there is nothing to configure". This issue is where that stops being true.applications/services.py:change_status,record_event— so an API that writes goes through the same path as the forms and the event log stays the single truth.Shape
captures(what today's token is),read,write, anddocuments:readon its own because files are the most sensitive thing Postulo holds. Same storage design as capture tokens — hash, prefix, shown once, last-used, revoke — plus an expiry. Migration: every existingCaptureTokenbecomes a token with thecapturesscope, so nothing anyone has installed stops working. Your details → Capture tokens becomes API tokens.for_user()exactly as the views are. Read side first: applications (list, filter, detail with timeline), companies, contacts, postings, reminders, CVs and cover letters (structured and rendered), uploads (metadata; the file itself behinddocuments:read), insights./api/docs): a machine-readable schema is what an MCP server and an extension author consume, and it is the documentation./api/v1; the capture endpoints do not move or change shape.Classification
Enhancement. Not breaking on one condition: existing capture tokens keep working unchanged through the migration to scoped tokens. Dropping that condition would make it a breaking change; it is not proposed.
Open questions