API#
Everything the console does in Hesperus goes through the same REST API as
Astraeus, at https://console.astralyx.cloud/api/v1, in JSON. This page
maps the Hesperus endpoints and who may call them; every endpoint, with
its bodies and examples, is in the
Hesperus API reference. Authentication,
conventions and the error format are in the
API Reference overview.
Base URLs#
| Scope | URL |
|---|---|
| A workspace on a cluster | https://console.astralyx.cloud/api/v1/orgs/{org}/workspaces/{ws}/clusters/{cluster}/api — written $API below |
| A workspace | https://console.astralyx.cloud/api/v1/orgs/{org}/workspaces/{ws} — written $CONSOLE below |
Authenticate with Authorization: Bearer <API token> (create one under
Account → API tokens). Names in paths and bodies are local to your
workspace: dev, not the namespace. Below, <org>, <workspace> and
<cluster> stand for yours (as in the console's address), and
ast_pat_… for your token:
$ export ASTRAEUS_TOKEN=ast_pat_…
$ export CONSOLE="https://console.astralyx.cloud/api/v1/orgs/<org>/workspaces/<workspace>"
$ export API="$CONSOLE/clusters/<cluster>/api"
Roles#
| Who | May |
|---|---|
| viewer | List and read notebooks, runtimes, the limits per person and the presets. Nothing that runs code: no opening, starting, connecting. |
| editor, admin | Create, change and delete notebooks; open them; create runtimes and environments; start, stop and delete any runtime of the workspace. |
| The runtime's owner, its members, workspace admins (all editors or admins) | SSH into it, open its IDE and its apps, name its apps. |
| The runtime's owner, workspace admins | Share it (its members). |
| admin | Set the limits per person; make a runtime for someone else (for); make one that never stops when idle (idle_timeout_minutes: 0). |
A notebook's Jupyter Server is every editor's: any editor may open any notebook of the workspace.
Endpoints#
Method and path (below $API unless said) |
What |
|---|---|
GET /notebooks · POST /notebooks |
List notebooks; create one {metadata, spec}. |
GET, PUT, DELETE /notebooks/{name} |
One notebook; change its spec; delete it (the file stays on the drive). |
POST /notebooks/{name}/open |
Open it: your runtime for it, started if need be → {notebook, runtime, reused}. |
GET /notebook-runtimes |
Runtimes, newest first. Filters: ?notebook=, ?state=, ?started_by=user:<id>. |
POST /notebook-runtimes |
Create a runtime or an environment {metadata, spec, for?} and start it. |
GET, DELETE /notebook-runtimes/{name} |
One runtime; delete it with its run (its drive keeps the files). |
POST /notebook-runtimes/{name}/stop · …/start |
Stop it (its GPUs are freed); start it again (a new run). |
POST /notebook-runtimes/{name}/ssh-certificates |
Sign your Ed25519 public key {public_key}: a certificate valid 8 hours for this runtime. |
GET /notebook-runtimes/{name}/ssh-sessions |
Its last 50 SSH sessions, newest first. |
GET /interactive/{task}/tcp/2222 |
A WebSocket carrying one SSH connection to the runtime (its ssh.tcp_path). |
PUT /notebook-runtimes/{name}/members |
Share it: {members: ["user:<id>"]}, replacing the list. |
PUT /notebook-runtimes/{name}/apps |
Name its apps: {apps: [{name, port}]}, replacing the list. |
POST /notebook-runtimes/{name}/access |
Whether you may reach its IDE (no port) or an app's port, and where. The console asks it for you. |
GET, PUT /notebook-limits/default |
The workspace's limits per person. |
GET /notebook-images |
The presets, {items, default}. |
POST $CONSOLE/clusters/{cluster}/runtime-links |
A link into a runtime's IDE or an app {runtime, port?, path?} → {url, origin, expires_at}: used once, within 60 seconds. |
Members by e-mail
The API names people as user:<id>. astra env share and the console
take an e-mail; with the API, find the id in
GET $CONSOLE/members (user_id).
Examples#
Make an environment with one GPU, then list who connected to it:
$ curl -fsS -X POST "$API/notebook-runtimes" -H "Authorization: Bearer $ASTRAEUS_TOKEN" \
-H 'content-type: application/json' \
-d '{"metadata": {"name": "dev"}, "spec": {"kind": "shell", "image": "pytorch", "resources": {"gpus": {"count": 1}}}}' \
| jq '{state: .status.state, reason: .status.reason, ssh}'
{
"state": "Pending",
"reason": "Started by user:7c1e2f4a-93b0-4d51-a6f2-0e8d3b9c1a55",
"ssh": {"user": "root", "port": 2222, "home": "/content/home/root", "workdir": "/content"}
}
$ curl -fsS "$API/notebook-runtimes/dev/ssh-sessions" -H "Authorization: Bearer $ASTRAEUS_TOKEN" \
| jq -r '.items[] | [.user, .client, .started_at, .duration_seconds] | @tsv'
user:7c1e2f4a-93b0-4d51-a6f2-0e8d3b9c1a55 astra 2026-10-02T09:14:03.112Z 1834
Give a runtime a credential as a variable (the console and astra do not
offer this; the credential hf must exist in the workspace):
$ curl -fsS -X POST "$API/notebook-runtimes" -H "Authorization: Bearer $ASTRAEUS_TOKEN" \
-H 'content-type: application/json' \
-d '{"metadata": {"name": "hf-dev"}, "spec": {"kind": "shell", "image": "huggingface", "resources": {"gpus": {"count": 1}},
"credentials": [{"credential": "hf", "key": "token", "env": "HF_TOKEN"}]}}' > /dev/null
Jupyter Server through a runtime#
A notebook's runtime serves Jupyter Server's REST API at its
status.proxy_path, reached below $API without /v1; the machine adds
the runtime's token. Editors and admins may use it:
$ TASK=$(curl -fsS "$API/notebook-runtimes/<runtime>" -H "Authorization: Bearer $ASTRAEUS_TOKEN" | jq -r .status.task)
$ curl -fsS "$API/interactive/$TASK/proxy/api/contents/notebooks" -H "Authorization: Bearer $ASTRAEUS_TOKEN" \
| jq -r '.content[].path'
notebooks/mnist.ipynb
Here <runtime> is a notebook's runtime that is Ready (its name is in
the notebook's status.last_runtime).
Errors#
Every code, with its message, is in Limits and errors.