distravia Release delivery · est. 2016

Documentation

Everything below is the v2 API. v1 keys still work and will keep working until at least 2028; new projects should start on v2.

Endpoints

Two public hosts, and one that is not public:

HostPurpose
dl.distravia.comRelease downloads for end users
cdn.distravia.comStatic assets for this site and these docs
issued per tenantControl plane, artifact ingest, registry replicas

The control plane is not on a public hostname. Yours is issued when the account is created and appears in the welcome mail and in every invoice; the examples below refer to it as $DISTRAVIA_API and to your ingest host as $DISTRAVIA_UPLOAD. Keeping it off a guessable name takes credential-stuffing traffic off the control plane entirely, which is worth more to us than the convenience of a memorable URL. The same goes for registry replicas: your replica host is yours, and it is not cdn.distravia.com.

The public hosts are HTTPS only. Each delivery region has its own hostname, and a hostname resolves to the one edge currently serving that region — so do not pin IP addresses: a hostname is re-pointed when an edge leaves rotation. Asking a public host for its root, or for a path that is not a release we carry, gets you this website and its 404 page respectively. That is expected; only the documented paths do anything else.

Authentication

A project token in the Authorization header. Tokens are scoped to one project and one of read, publish or admin.

curl -sS "$DISTRAVIA_API/v2/projects/acme-studio" \
  -H "Authorization: Bearer $DISTRAVIA_TOKEN"

Uploading a version

Create the version, then PUT the file. Uploads are resumable: repeat the PUT with a Content-Range header and we continue where the transfer stopped.

curl -sS -X POST "$DISTRAVIA_API/v2/projects/acme-studio/versions" \
  -H "Authorization: Bearer $DISTRAVIA_TOKEN" \
  -d '{"version":"4.2.1","platform":"win-x64","sha256":"9f2c…"}'

curl -sS -X PUT "$DISTRAVIA_UPLOAD/v2/acme-studio/4.2.1/win-x64" \
  -H "Authorization: Bearer $DISTRAVIA_TOKEN" \
  --data-binary @AcmeStudio-4.2.1-x64.msi

The sha256 you declare is checked on ingest. A mismatch fails the upload; we never store an artifact we cannot verify.

Promoting a channel

curl -sS -X PUT "$DISTRAVIA_API/v2/projects/acme-studio/channels/stable" \
  -H "Authorization: Bearer $DISTRAVIA_TOKEN" \
  -d '{"version":"4.2.1"}'

Rolling back is the same call with the previous version. Both take effect at every edge within about 40 seconds.

Download URLs

Public channels resolve directly:

https://dl.distravia.com/acme-studio/stable/win-x64
https://dl.distravia.com/acme-studio/4.2.1/win-x64

Gated channels need a signed URL, which your own licence server mints with its project key. TTL is yours to choose, up to 24 hours.

GET $DISTRAVIA_API/v2/projects/acme-studio/sign?path=/stable/win-x64&ttl=900

Failover

A download that stalls or returns 5xx should be retried against the alternate hostname your tenant documentation lists for that region, with a Range header so the transfer resumes instead of starting again. Our client libraries do this for you; if you implement it yourself, retry twice per region before you give up on one.

Rate limits

ScopeLimit
Control plane, per token600 req/min
Channel promotion, per project30 /hour
Signing, per token10,000 req/min
Downloadsunmetered
Downloads are never rate limited by us. If you need to throttle your own users, do it in the signing step — that is what the TTL and per-key counters are for.

Retired

POST $DISTRAVIA_API/v1/publish is deprecated in favour of the two-step create-then-PUT flow above. It still works. It will not gain delta generation.