Skip to main content
POST
Resolve and pin project dependencies

Authorizations

Authorization
string
header
required

Use a JWT bearer token or a Veryfront API key in the Authorization header.

Path Parameters

project_reference
string
required

Project slug, UUID, or domain

Body

application/json
specifiers
string[]
required

npm package specifiers to resolve. Each entry may be a bare name, a name with an inline exact version, or a name with a semver range (for example, "react", "[email protected]", "zod@^3", "@radix-ui/react-dialog").

Required array length: 1 - 100 elements
Required string length: 1 - 200
Example:
branch
string

Branch name or UUID, 1-255 characters without surrounding whitespace. Omit for main; selected package.json receives the resolved pins.

Required string length: 1 - 255
Example:

"feature-a"

expected_declarations
object

Package declarations observed by the caller, at most 100 entries with string values up to 200 characters. A null value means the package was absent. When supplied, every requested package must be present and stale declarations are not overwritten.

Example:

Response

Resolved pins (may be a partial set if some specifiers failed)

pins
object
required

Resolved exact version pins keyed by package name. Includes both newly-written pins and pre-existing exact pins for all requested specifiers that were successfully resolved.

Example:
persisted
boolean
required

True when eligible pins were persisted to package.json or no eligible write was needed. False means persistence failed; pins retain intended values and the caller may retry.

skipped
object
required

Requested packages not written because the current declaration no longer matched the caller snapshot.

Example: