curl --request POST \
--url http://localhost:3000/api/v1/reports \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"workspaceId": "wsp_…",
"projectId": "prj_…",
"localReportId": "rpt_9f0c…",
"effortRequested": "auto",
"effortResolved": "high",
"projectName": "vuln-shop",
"agent": {
"name": "claude-code",
"version": "2.1.0",
"model": "claude-opus-5"
},
"host": {
"osFamily": "darwin",
"arch": "arm64",
"cliVersion": "0.1.0"
}
}
'import requests
url = "http://localhost:3000/api/v1/reports"
payload = {
"workspaceId": "wsp_…",
"projectId": "prj_…",
"localReportId": "rpt_9f0c…",
"effortRequested": "auto",
"effortResolved": "high",
"projectName": "vuln-shop",
"agent": {
"name": "claude-code",
"version": "2.1.0",
"model": "claude-opus-5"
},
"host": {
"osFamily": "darwin",
"arch": "arm64",
"cliVersion": "0.1.0"
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
workspaceId: 'wsp_…',
projectId: 'prj_…',
localReportId: 'rpt_9f0c…',
effortRequested: 'auto',
effortResolved: 'high',
projectName: 'vuln-shop',
agent: {name: 'claude-code', version: '2.1.0', model: 'claude-opus-5'},
host: {osFamily: 'darwin', arch: 'arm64', cliVersion: '0.1.0'}
})
};
fetch('http://localhost:3000/api/v1/reports', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_PORT => "3000",
CURLOPT_URL => "http://localhost:3000/api/v1/reports",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'workspaceId' => 'wsp_…',
'projectId' => 'prj_…',
'localReportId' => 'rpt_9f0c…',
'effortRequested' => 'auto',
'effortResolved' => 'high',
'projectName' => 'vuln-shop',
'agent' => [
'name' => 'claude-code',
'version' => '2.1.0',
'model' => 'claude-opus-5'
],
'host' => [
'osFamily' => 'darwin',
'arch' => 'arm64',
'cliVersion' => '0.1.0'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "http://localhost:3000/api/v1/reports"
payload := strings.NewReader("{\n \"workspaceId\": \"wsp_…\",\n \"projectId\": \"prj_…\",\n \"localReportId\": \"rpt_9f0c…\",\n \"effortRequested\": \"auto\",\n \"effortResolved\": \"high\",\n \"projectName\": \"vuln-shop\",\n \"agent\": {\n \"name\": \"claude-code\",\n \"version\": \"2.1.0\",\n \"model\": \"claude-opus-5\"\n },\n \"host\": {\n \"osFamily\": \"darwin\",\n \"arch\": \"arm64\",\n \"cliVersion\": \"0.1.0\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("http://localhost:3000/api/v1/reports")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"workspaceId\": \"wsp_…\",\n \"projectId\": \"prj_…\",\n \"localReportId\": \"rpt_9f0c…\",\n \"effortRequested\": \"auto\",\n \"effortResolved\": \"high\",\n \"projectName\": \"vuln-shop\",\n \"agent\": {\n \"name\": \"claude-code\",\n \"version\": \"2.1.0\",\n \"model\": \"claude-opus-5\"\n },\n \"host\": {\n \"osFamily\": \"darwin\",\n \"arch\": \"arm64\",\n \"cliVersion\": \"0.1.0\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("http://localhost:3000/api/v1/reports")
http = Net::HTTP.new(url.host, url.port)
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"workspaceId\": \"wsp_…\",\n \"projectId\": \"prj_…\",\n \"localReportId\": \"rpt_9f0c…\",\n \"effortRequested\": \"auto\",\n \"effortResolved\": \"high\",\n \"projectName\": \"vuln-shop\",\n \"agent\": {\n \"name\": \"claude-code\",\n \"version\": \"2.1.0\",\n \"model\": \"claude-opus-5\"\n },\n \"host\": {\n \"osFamily\": \"darwin\",\n \"arch\": \"arm64\",\n \"cliVersion\": \"0.1.0\"\n }\n}"
response = http.request(request)
puts response.read_body{
"reportId": "<string>",
"reportUrl": "<string>",
"state": "live",
"expiresAt": "2023-11-07T05:31:56Z",
"quota": {
"eligible": true,
"daily": {
"used": 123,
"limit": 123,
"resetsAt": "2023-11-07T05:31:56Z"
},
"weekly": {
"used": 123,
"limit": 123,
"resetsAt": "2023-11-07T05:31:56Z"
},
"retentionDays": 123
}
}{
"reportId": "rep_…",
"reportUrl": "https://myrqen.cc/app/reports/rep_…",
"state": "live",
"expiresAt": "2026-09-10T12:00:00.000Z",
"quota": {
"eligible": true,
"daily": {
"used": 3,
"limit": 5,
"resetsAt": "2026-08-21T06:00:00.000Z"
},
"weekly": {
"used": 8,
"limit": 15,
"resetsAt": "2026-08-24T06:00:00.000Z"
},
"retentionDays": 21,
"plan": "free"
}
}{
"error": {
"code": "SYNC_WEEKLY_LIMIT_REACHED",
"message": "Cloud report limit reached. This scan stays local.",
"requestId": "8f14e45f-ceea-467a-9f8b-2b6b2b6a1f2c",
"details": {
"weekly": {
"used": 15,
"limit": 15,
"resetsAt": "2026-08-24T06:00:00.000Z"
}
}
}
}{
"error": {
"code": "SYNC_WEEKLY_LIMIT_REACHED",
"message": "Cloud report limit reached. This scan stays local.",
"requestId": "8f14e45f-ceea-467a-9f8b-2b6b2b6a1f2c",
"details": {
"weekly": {
"used": 15,
"limit": 15,
"resetsAt": "2026-08-24T06:00:00.000Z"
}
}
}
}{
"error": {
"code": "SYNC_WEEKLY_LIMIT_REACHED",
"message": "Cloud report limit reached. This scan stays local.",
"requestId": "8f14e45f-ceea-467a-9f8b-2b6b2b6a1f2c",
"details": {
"weekly": {
"used": 15,
"limit": 15,
"resetsAt": "2026-08-24T06:00:00.000Z"
}
}
}
}{
"error": {
"code": "SYNC_WEEKLY_LIMIT_REACHED",
"message": "Cloud report limit reached. This scan stays local.",
"requestId": "8f14e45f-ceea-467a-9f8b-2b6b2b6a1f2c",
"details": {
"weekly": {
"used": 15,
"limit": 15,
"resetsAt": "2026-08-24T06:00:00.000Z"
}
}
}
}Create a cloud report shell
Creates the report shell and returns a live URL immediately. The sync unit is reserved here and spent at finalize, so an object-storage failure in the upload leg never burns one of the day’s cloud reports.
Idempotent on localReportId: a retried request reuses the same reservation and never charges twice, and returns 200 instead of 201. Source is never accepted here.
curl --request POST \
--url http://localhost:3000/api/v1/reports \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"workspaceId": "wsp_…",
"projectId": "prj_…",
"localReportId": "rpt_9f0c…",
"effortRequested": "auto",
"effortResolved": "high",
"projectName": "vuln-shop",
"agent": {
"name": "claude-code",
"version": "2.1.0",
"model": "claude-opus-5"
},
"host": {
"osFamily": "darwin",
"arch": "arm64",
"cliVersion": "0.1.0"
}
}
'import requests
url = "http://localhost:3000/api/v1/reports"
payload = {
"workspaceId": "wsp_…",
"projectId": "prj_…",
"localReportId": "rpt_9f0c…",
"effortRequested": "auto",
"effortResolved": "high",
"projectName": "vuln-shop",
"agent": {
"name": "claude-code",
"version": "2.1.0",
"model": "claude-opus-5"
},
"host": {
"osFamily": "darwin",
"arch": "arm64",
"cliVersion": "0.1.0"
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
workspaceId: 'wsp_…',
projectId: 'prj_…',
localReportId: 'rpt_9f0c…',
effortRequested: 'auto',
effortResolved: 'high',
projectName: 'vuln-shop',
agent: {name: 'claude-code', version: '2.1.0', model: 'claude-opus-5'},
host: {osFamily: 'darwin', arch: 'arm64', cliVersion: '0.1.0'}
})
};
fetch('http://localhost:3000/api/v1/reports', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_PORT => "3000",
CURLOPT_URL => "http://localhost:3000/api/v1/reports",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'workspaceId' => 'wsp_…',
'projectId' => 'prj_…',
'localReportId' => 'rpt_9f0c…',
'effortRequested' => 'auto',
'effortResolved' => 'high',
'projectName' => 'vuln-shop',
'agent' => [
'name' => 'claude-code',
'version' => '2.1.0',
'model' => 'claude-opus-5'
],
'host' => [
'osFamily' => 'darwin',
'arch' => 'arm64',
'cliVersion' => '0.1.0'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "http://localhost:3000/api/v1/reports"
payload := strings.NewReader("{\n \"workspaceId\": \"wsp_…\",\n \"projectId\": \"prj_…\",\n \"localReportId\": \"rpt_9f0c…\",\n \"effortRequested\": \"auto\",\n \"effortResolved\": \"high\",\n \"projectName\": \"vuln-shop\",\n \"agent\": {\n \"name\": \"claude-code\",\n \"version\": \"2.1.0\",\n \"model\": \"claude-opus-5\"\n },\n \"host\": {\n \"osFamily\": \"darwin\",\n \"arch\": \"arm64\",\n \"cliVersion\": \"0.1.0\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("http://localhost:3000/api/v1/reports")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"workspaceId\": \"wsp_…\",\n \"projectId\": \"prj_…\",\n \"localReportId\": \"rpt_9f0c…\",\n \"effortRequested\": \"auto\",\n \"effortResolved\": \"high\",\n \"projectName\": \"vuln-shop\",\n \"agent\": {\n \"name\": \"claude-code\",\n \"version\": \"2.1.0\",\n \"model\": \"claude-opus-5\"\n },\n \"host\": {\n \"osFamily\": \"darwin\",\n \"arch\": \"arm64\",\n \"cliVersion\": \"0.1.0\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("http://localhost:3000/api/v1/reports")
http = Net::HTTP.new(url.host, url.port)
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"workspaceId\": \"wsp_…\",\n \"projectId\": \"prj_…\",\n \"localReportId\": \"rpt_9f0c…\",\n \"effortRequested\": \"auto\",\n \"effortResolved\": \"high\",\n \"projectName\": \"vuln-shop\",\n \"agent\": {\n \"name\": \"claude-code\",\n \"version\": \"2.1.0\",\n \"model\": \"claude-opus-5\"\n },\n \"host\": {\n \"osFamily\": \"darwin\",\n \"arch\": \"arm64\",\n \"cliVersion\": \"0.1.0\"\n }\n}"
response = http.request(request)
puts response.read_body{
"reportId": "<string>",
"reportUrl": "<string>",
"state": "live",
"expiresAt": "2023-11-07T05:31:56Z",
"quota": {
"eligible": true,
"daily": {
"used": 123,
"limit": 123,
"resetsAt": "2023-11-07T05:31:56Z"
},
"weekly": {
"used": 123,
"limit": 123,
"resetsAt": "2023-11-07T05:31:56Z"
},
"retentionDays": 123
}
}{
"reportId": "rep_…",
"reportUrl": "https://myrqen.cc/app/reports/rep_…",
"state": "live",
"expiresAt": "2026-09-10T12:00:00.000Z",
"quota": {
"eligible": true,
"daily": {
"used": 3,
"limit": 5,
"resetsAt": "2026-08-21T06:00:00.000Z"
},
"weekly": {
"used": 8,
"limit": 15,
"resetsAt": "2026-08-24T06:00:00.000Z"
},
"retentionDays": 21,
"plan": "free"
}
}{
"error": {
"code": "SYNC_WEEKLY_LIMIT_REACHED",
"message": "Cloud report limit reached. This scan stays local.",
"requestId": "8f14e45f-ceea-467a-9f8b-2b6b2b6a1f2c",
"details": {
"weekly": {
"used": 15,
"limit": 15,
"resetsAt": "2026-08-24T06:00:00.000Z"
}
}
}
}{
"error": {
"code": "SYNC_WEEKLY_LIMIT_REACHED",
"message": "Cloud report limit reached. This scan stays local.",
"requestId": "8f14e45f-ceea-467a-9f8b-2b6b2b6a1f2c",
"details": {
"weekly": {
"used": 15,
"limit": 15,
"resetsAt": "2026-08-24T06:00:00.000Z"
}
}
}
}{
"error": {
"code": "SYNC_WEEKLY_LIMIT_REACHED",
"message": "Cloud report limit reached. This scan stays local.",
"requestId": "8f14e45f-ceea-467a-9f8b-2b6b2b6a1f2c",
"details": {
"weekly": {
"used": 15,
"limit": 15,
"resetsAt": "2026-08-24T06:00:00.000Z"
}
}
}
}{
"error": {
"code": "SYNC_WEEKLY_LIMIT_REACHED",
"message": "Cloud report limit reached. This scan stays local.",
"requestId": "8f14e45f-ceea-467a-9f8b-2b6b2b6a1f2c",
"details": {
"weekly": {
"used": 15,
"limit": 15,
"resetsAt": "2026-08-24T06:00:00.000Z"
}
}
}
}Authorizations
The CLI's device credential, obtained once from the device-link exchange and stored in the OS keystore. Sent as Authorization: Bearer myrq_dev_…. The server never trusts a CLI-supplied user id — identity comes from the credential row.
Body
The CLI's local report id. Also the idempotency key for the quota reservation.
low, high, xhigh, ultra, auto Show child attributes
Show child attributes
200low, high, xhigh, ultra Show child attributes
Show child attributes
Response
The shell already existed for this localReportId.