Protocol V2 · Registry V4

DSH API V2

One package protocol, one registry model and one resolver. The remote API only discovers and resolves packages; installation always executes in the local DSH runtime after explicit confirmation.

Canonical package identity

Every package is identified by (type, id). The canonical coordinate is <type>:<id>@<semver-range>. Supported types are plugin, mcp, skill, and agent. There is no implicit plugin type and no legacy github: syntax.

skill:owner/example@^1.2.0
agent:owner/agent@*
mcp:owner/server@2.0.0

Response contract

Success is always { data, meta }. Failure is always { error: { code, message, details? }, meta }. meta.request_id is present on API responses and Registry-backed endpoints also expose the active Registry revision.

{
  "data": { ... },
  "meta": {
    "request_id": "...",
    "registry_revision": "..."
  }
}

Endpoints

MethodPathPurpose
GET/api/v2API V2 capability map
GET/api/v2/capabilitiesProtocol, package type and channel capabilities
GET/api/v2/healthRegistry V4 health and revision
GET/api/v2/packages?q=&type=&limit=Package collection
GET/api/v2/packages/:type/:idCanonical package + releases
GET/api/v2/packages/:type/:id/releasesPackage release history
GET/api/v2/packages/:type/:id/releases/:versionOne immutable release
GET/api/v2/search?q=&type=&limit=Registry V4 search
POST/api/v2/resolveResolve package + dependency graph
POST/api/v2/install-planBuild a local-only install plan
GET/api/v2/publishersPublisher identities
GET/api/v2/publishers/:idPublisher + package portfolio
GET/api/v2/advisoriesSecurity advisories
GET/api/v2/advisories/:idSecurity advisory detail
GET/api/v2/registry/revisionRegistry V4 revision
GET/api/v2/registry/delta?from=:revisionDelta negotiation / full-refresh signal
POST/api/v2/mcpMCP Tools V2 JSON-RPC endpoint

Resolve

curl -X POST "https://dsh-go.pages.dev/api/v2/resolve"   -H "Content-Type: application/json"   -d '{
  "request": {
    "type": "skill",
    "id": "owner/example",
    "range": "^1.2.0",
    "channel": "stable"
  },
  "environment": {
    "dsh_version": "1.0.0",
    "os": "linux",
    "arch": "x64"
  }
}'

The resolver returns a deterministic dependency graph, install order, aggregated permissions and a resolution_hash. Revoked, yanked and critical-advisory releases are fail-closed.

Install plan

curl -X POST "https://dsh-go.pages.dev/api/v2/install-plan"   -H "Content-Type: application/json"   -d '{"type":"skill","id":"owner/example","range":"^1.2.0","channel":"stable"}'

The returned plan contains the canonical local command dsh package install ... and dsh://package/install deep link. The API never performs the installation.

MCP Tools V2

The MCP endpoint exposes only canonical Registry V4 tools: package_search, package_get, package_releases, package_resolve, package_install_plan, publisher_get, advisory_get, and registry_status.

curl -X POST "https://dsh-go.pages.dev/api/v2/mcp"   -H "Content-Type: application/json"   -d '{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "package_search",
    "arguments": {
      "query": "agent",
      "type": "agent",
      "limit": 10
    }
  }
}'

Distribution

Breaking upgrade policy

API V1 is removed. Clients must use API V2, Registry V4, Protocol V2 and canonical package coordinates. There is no compatibility proxy or dual-write migration surface.