Documentation
Everything below is the v2 API. v1 keys still work and will keep working until at least 2028; new projects should start on v2.
Endpoints
Two public hosts, and one that is not public:
| Host | Purpose |
|---|---|
dl.distravia.com | Release downloads for end users |
cdn.distravia.com | Static assets for this site and these docs |
| issued per tenant | Control plane, artifact ingest, registry replicas |
The control plane is not on a public hostname. Yours is issued when
the account is created and appears in the welcome mail and in every invoice; the examples
below refer to it as $DISTRAVIA_API and to your ingest host as
$DISTRAVIA_UPLOAD. Keeping it off a guessable name takes credential-stuffing
traffic off the control plane entirely, which is worth more to us than the convenience of
a memorable URL. The same goes for registry replicas: your replica host is yours, and it
is not cdn.distravia.com.
The public hosts are HTTPS only. Each delivery region has its own hostname, and a hostname resolves to the one edge currently serving that region — so do not pin IP addresses: a hostname is re-pointed when an edge leaves rotation. Asking a public host for its root, or for a path that is not a release we carry, gets you this website and its 404 page respectively. That is expected; only the documented paths do anything else.
Authentication
A project token in the Authorization header. Tokens are scoped to one
project and one of read, publish or admin.
curl -sS "$DISTRAVIA_API/v2/projects/acme-studio" \ -H "Authorization: Bearer $DISTRAVIA_TOKEN"
Uploading a version
Create the version, then PUT the file. Uploads are resumable: repeat the PUT with a
Content-Range header and we continue where the transfer stopped.
curl -sS -X POST "$DISTRAVIA_API/v2/projects/acme-studio/versions" \
-H "Authorization: Bearer $DISTRAVIA_TOKEN" \
-d '{"version":"4.2.1","platform":"win-x64","sha256":"9f2c…"}'
curl -sS -X PUT "$DISTRAVIA_UPLOAD/v2/acme-studio/4.2.1/win-x64" \
-H "Authorization: Bearer $DISTRAVIA_TOKEN" \
--data-binary @AcmeStudio-4.2.1-x64.msi
The sha256 you declare is checked on ingest. A mismatch fails the upload;
we never store an artifact we cannot verify.
Promoting a channel
curl -sS -X PUT "$DISTRAVIA_API/v2/projects/acme-studio/channels/stable" \
-H "Authorization: Bearer $DISTRAVIA_TOKEN" \
-d '{"version":"4.2.1"}'
Rolling back is the same call with the previous version. Both take effect at every edge within about 40 seconds.
Download URLs
Public channels resolve directly:
https://dl.distravia.com/acme-studio/stable/win-x64 https://dl.distravia.com/acme-studio/4.2.1/win-x64
Gated channels need a signed URL, which your own licence server mints with its project key. TTL is yours to choose, up to 24 hours.
GET $DISTRAVIA_API/v2/projects/acme-studio/sign?path=/stable/win-x64&ttl=900
Failover
A download that stalls or returns 5xx should be retried against the alternate
hostname your tenant documentation lists for that region, with a Range
header so the transfer resumes instead of starting again. Our client libraries do this
for you; if you implement it yourself, retry twice per region before you give up on
one.
Rate limits
| Scope | Limit |
|---|---|
| Control plane, per token | 600 req/min |
| Channel promotion, per project | 30 /hour |
| Signing, per token | 10,000 req/min |
| Downloads | unmetered |
Retired
POST $DISTRAVIA_API/v1/publish is deprecated in favour of the two-step create-then-PUT
flow above. It still works. It will not gain delta generation.