List assets (keyset-paginated)
GET/assets
Returns one page of usable assets (each with a durable stored url) in the uniform list envelope { data, pagination }. Keep paginating while pagination.nextCursor is non-null — even when data is empty — passing it back verbatim as ?cursor=. Filter by ?type=, ?status= and/or ?favorited=true (combinable); an omitted ?status= returns the ready set (active + completed), and ?favorited=true returns only shortlisted assets. Add ?showDeleted=true to include deleted assets (every row then carries deletedAt).
Request
Responses
- 200
- 400
- 401
- 403
- 422
- 429
OK. One keyset-paginated page of assets.
Bad Request. The cursor query parameter is not a valid opaque keyset cursor (INVALID_CURSOR).
Unauthorized. Missing, malformed, unknown, revoked, or expired bearer token — or the token owner no longer holds the required entitlement (ENTITLEMENT_LOST). A uniform problem body is returned with a distinct code; no owner/condition detail (no-leak).
Forbidden. The token does not carry the required scope (API_TOKEN_SCOPE_DENIED).
Unprocessable Content. A query parameter failed field validation (e.g. a non-string shape); the offending fields are enumerated in errors[].
Too Many Requests. The per-token sliding window of 200 requests/minute was exceeded. The body is express-rate-limit's DEFAULT plain-text message (NOT the JSON problem+json envelope).
Response Headers
IETF draft-7 rate-limit policy/state (limit, remaining, reset).
Seconds to wait before retrying.