> ## Documentation Index
> Fetch the complete documentation index at: https://openworklabs.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For agents: install the OpenWork desktop app with `brew install --cask openwork` (macOS) or from https://openworklabs.com/download. Do not run `npx openwork`; the npm package named `openwork` is a different project.
> Connect an agent to OpenWork with the MCP Gateway: `claude mcp add --transport http openwork https://api.openworklabs.com/mcp/agent`. Teams sign up at https://app.openworklabs.com?mode=sign-up.
> Step-by-step agent guide: https://openworklabs.com/docs/start-here/use-openwork-from-an-ai-agent.md
> OpenWork in Slack is private alpha for approved organizations. Setup guide: https://openworklabs.com/docs/slack/overview.md. Agent skill: https://openworklabs.com/.well-known/agent-skills/set-up-openwork-slack/SKILL.md.

# Prepare an install, retry or approved update

> Creates or reuses an installer run pinned to the published release and returns a console approval link (install) or an account-checked cloud shell command (retry, update).



## OpenAPI

````yaml /openapi.json post /v1/managed-deployments/{deploymentId}/launch
openapi: 3.1.0
info:
  title: Den API
  description: >-
    OpenAPI spec for the Den control plane API.


    Authentication:

    - API keys (they start with `den_`) go in the `x-api-key` header as the raw
    value. Do not send them as `Authorization: Bearer`; that header only accepts
    Den session tokens, so an API key there returns 401.
      Example: `curl https://api.openworklabs.com/v1/me -H "x-api-key: den_..."`.
      API keys resolve to the issuing user and the organization member they were scoped to when created, so they can call ordinary user and organization routes without a separate signed-in session.
    - Use `Authorization: Bearer <session-token>` for user-authenticated routes
    that require a Den session.

    - Session-only flows still require a signed-in user session, including
    organization creation, invitation acceptance, active-organization switching,
    and MCP token minting.

    - Public routes like health and documentation do not require authentication.


    Swagger tip: use the security schemes in the Authorize dialog to set
    `denApiKey` (your API key) or `bearerAuth` (a session token) before trying
    protected endpoints.
  version: 0.18.46
  contact:
    name: OpenWork
    url: https://openworklabs.com
    email: team@openworklabs.com
  license:
    name: OpenWork Enterprise Edition License
    url: https://github.com/different-ai/openwork/blob/dev/ee/LICENSE
servers:
  - url: https://api.openworklabs.com
security:
  - denApiKey: []
  - bearerAuth: []
tags:
  - name: System
    description: >-
      Service health, readiness, API documentation, and desktop version
      metadata.
  - name: Authentication
    description: >-
      Sign-in discovery, administrator bootstrap, OAuth provider connections,
      and MCP token minting.
  - name: OAuth
    description: >-
      OAuth 2.0 / OpenID Connect authorization-server and protected-resource
      metadata and dynamic client registration (RFC 8414, RFC 9728, RFC 7591),
      used by MCP clients.
  - name: SCIM
    description: >-
      SCIM 2.0 provisioning endpoints for identity providers (RFC 7644) and the
      organization SCIM connector management routes.
  - name: SSO
    description: Organization single sign-on connector management routes.
  - name: Bootstrap
    description: Agent-first provisional workspace setup routes.
  - name: Users
    description: Current user and membership routes.
  - name: Organizations
    description: Organization creation, context, brand assets, and install links.
  - name: Invitations
    description: Invitation preview, acceptance, creation, and cancellation routes.
  - name: Members
    description: Organization member management routes.
  - name: Roles
    description: Organization custom role management routes.
  - name: Teams
    description: Organization team management routes.
  - name: API Keys
    description: Organization API key management routes.
  - name: Desktop Policies
    description: Desktop app policies applied to the organization, members, or teams.
  - name: LLM Providers
    description: Organization LLM provider catalog, configuration, and access routes.
  - name: Inference
    description: Organization inference settings.
  - name: Inference Providers
    description: >-
      Organization inference Gateway providers, model groups, credential sets,
      access grants, member connections, and usage.
  - name: Gateway Usage Limits
    description: >-
      Estimated-cost policies, independent member calendar buckets, assignments,
      and audited usage-extension requests.
  - name: Cloud
    description: Organization Cloud instance lifecycle and browser gateway resolution.
  - name: Workers
    description: >-
      List and delete the organization's workers, including OpenWork Web
      instances.
  - name: Worker Activity
    description: Worker heartbeat and activity reporting routes.
  - name: Managed deployments
    description: >-
      OpenWork installations in an organization's own cloud account: launch
      approval, installer milestones and health reports.
  - name: Automations
    description: Scheduled Automations, their runs, and desktop runner presence.
  - name: Workbot
    description: The signed-in member's single Workbot conversation.
  - name: Workflows
    description: Saved Workflows (Code Mode scripts), their versions, snapshots, and views.
  - name: Workflow Runs
    description: Durable Workflow run history.
  - name: Codemode Runs
    description: Generated Artifact views produced by Code Mode runs.
  - name: Apps
    description: >-
      Saved reusable apps built from Workflows and Artifact views, and their
      sharing.
  - name: Config Objects
    description: >-
      Versioned configuration objects (skills, workflows, and other plugin
      content).
  - name: Plugins
    description: Plugin packages, access grants, and imports.
  - name: Marketplaces
    description: Marketplaces that distribute plugins to members and teams.
  - name: Resources
    description: >-
      Aggregated snapshot of the resources and marketplace capabilities
      available to the caller.
  - name: Dashboards
    description: Shared dashboards and their access grants.
  - name: Capability Sources
    description: >-
      Native provider capabilities (Google Workspace, Microsoft 365) and
      external MCP connections executed as the calling member.
  - name: Direct uploads
    description: Multipart uploads that stream workspace files straight to a provider.
  - name: Connectors
    description: >-
      Connector accounts and instances (GitHub and other sources) and their sync
      state.
  - name: GitHub
    description: >-
      GitHub App installation, repository discovery, and plugin import from
      GitHub.
  - name: Diagnostics
    description: Controlled egress diagnostics for self-hosted deployments.
  - name: Telemetry
    description: Telemetry event ingestion and adoption analytics.
  - name: Webhooks
    description: Signed inbound webhooks from third-party providers.
  - name: Admin
    description: Platform administration routes for allowlisted OpenWork administrators.
  - name: Deprecated
    description: Removed features that answer with 410 or an empty result for old clients.
paths:
  /v1/managed-deployments/{deploymentId}/launch:
    post:
      tags:
        - Managed deployments
      summary: Prepare an install, retry or approved update
      description: >-
        Creates or reuses an installer run pinned to the published release and
        returns a console approval link (install) or an account-checked cloud
        shell command (retry, update).
      operationId: postV1ManagedDeploymentsByDeploymentIdLaunch
      parameters:
        - in: path
          name: deploymentId
          schema:
            type: string
            format: uuid
            pattern: >-
              ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
          required: true
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                kind:
                  default: install
                  type: string
                  enum:
                    - install
                    - update
                    - retry
              additionalProperties: false
      responses:
        '200':
          description: Prepare an install, retry or approved update
          content:
            application/json:
              schema:
                type: object
                properties:
                  deployment:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                        pattern: >-
                          ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                      name:
                        type: string
                      provider:
                        type: string
                        enum:
                          - aws
                          - azure
                          - gcp
                      target:
                        type: object
                        properties:
                          accountId:
                            type: string
                            pattern: ^\d{12}$
                          region:
                            type: string
                            enum:
                              - us-east-1
                              - us-east-2
                              - us-west-2
                              - eu-west-1
                              - eu-central-1
                              - ap-southeast-1
                              - ap-southeast-2
                          route53ZoneId:
                            type: string
                            pattern: ^Z[A-Z0-9]{1,31}$
                        required:
                          - accountId
                          - region
                          - route53ZoneId
                        additionalProperties: false
                      domainName:
                        type: string
                      ownerEmail:
                        type: string
                      size:
                        type: string
                        const: small
                      updateMode:
                        type: string
                        const: approval
                      createdAt:
                        type: string
                        format: date-time
                        pattern: >-
                          ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                      webUrl:
                        type: string
                        format: uri
                      consoleUrl:
                        type: string
                        format: uri
                      installedVersion:
                        anyOf:
                          - type: string
                            maxLength: 80
                            pattern: ^\d+\.\d+\.\d+(?:-[0-9A-Za-z.-]+)?$
                          - type: 'null'
                      availableVersion:
                        anyOf:
                          - type: string
                            maxLength: 80
                            pattern: ^\d+\.\d+\.\d+(?:-[0-9A-Za-z.-]+)?$
                          - type: 'null'
                      updateAvailable:
                        type: boolean
                      health:
                        type: object
                        properties:
                          state:
                            type: string
                            enum:
                              - operational
                              - degraded
                              - down
                              - not_reporting
                              - awaiting_report
                          reportedAt:
                            anyOf:
                              - type: string
                                format: date-time
                                pattern: >-
                                  ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                              - type: 'null'
                          version:
                            anyOf:
                              - type: string
                                maxLength: 80
                                pattern: ^\d+\.\d+\.\d+(?:-[0-9A-Za-z.-]+)?$
                              - type: 'null'
                          checks:
                            type: array
                            items:
                              type: object
                              properties:
                                id:
                                  type: string
                                  enum:
                                    - api_health
                                    - database_ready
                                    - web_available
                                    - services_running
                                    - load_balancer_targets
                                    - database_instance
                                    - database_storage
                                    - database_backups
                                    - certificate
                                status:
                                  type: string
                                  enum:
                                    - ok
                                    - warning
                                    - failing
                                    - unknown
                                value:
                                  type: number
                                  minimum: 0
                                  maximum: 1000000000
                                total:
                                  type: number
                                  minimum: 0
                                  maximum: 1000000000
                                code:
                                  type: string
                                  enum:
                                    - http_error
                                    - unreachable
                                    - slow
                                    - not_running
                                    - unhealthy
                                    - unavailable
                                    - permission_denied
                                    - low_storage
                                    - stale_backup
                                    - backups_disabled
                                    - not_issued
                                    - expiring
                                    - expired
                              required:
                                - id
                                - status
                              additionalProperties: false
                        required:
                          - state
                          - reportedAt
                          - version
                          - checks
                      run:
                        anyOf:
                          - type: object
                            properties:
                              id:
                                type: string
                                format: uuid
                                pattern: >-
                                  ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                              kind:
                                type: string
                                enum:
                                  - install
                                  - update
                                  - retry
                              version:
                                type: string
                              state:
                                type: string
                                enum:
                                  - awaiting_approval
                                  - provisioning
                                  - ready
                                  - failed
                              createdAt:
                                type: string
                                format: date-time
                                pattern: >-
                                  ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                              lastSeenAt:
                                anyOf:
                                  - type: string
                                    format: date-time
                                    pattern: >-
                                      ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                                  - type: 'null'
                              expiresAt:
                                type: string
                                format: date-time
                                pattern: >-
                                  ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                              expired:
                                type: boolean
                              events:
                                type: array
                                items:
                                  type: object
                                  properties:
                                    sequence:
                                      type: integer
                                      minimum: 1
                                      maximum: 100
                                    step:
                                      type: string
                                      enum:
                                        - runner_connected
                                        - release_verified
                                        - account_verified
                                        - infrastructure_applied
                                        - services_ready
                                        - health_verified
                                    outcome:
                                      type: string
                                      enum:
                                        - succeeded
                                        - failed
                                    errorCode:
                                      type: string
                                      enum:
                                        - release_verification_failed
                                        - infrastructure_failed
                                        - certificate_failed
                                        - service_unhealthy
                                        - health_check_failed
                                        - runner_failed
                                    receivedAt:
                                      type: string
                                      format: date-time
                                      pattern: >-
                                        ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                                  required:
                                    - sequence
                                    - step
                                    - outcome
                                    - receivedAt
                                  additionalProperties: false
                            required:
                              - id
                              - kind
                              - version
                              - state
                              - createdAt
                              - lastSeenAt
                              - expiresAt
                              - expired
                              - events
                          - type: 'null'
                    required:
                      - id
                      - name
                      - provider
                      - target
                      - domainName
                      - ownerEmail
                      - size
                      - updateMode
                      - createdAt
                      - webUrl
                      - consoleUrl
                      - installedVersion
                      - availableVersion
                      - updateAvailable
                      - health
                      - run
                  kind:
                    type: string
                    enum:
                      - install
                      - update
                      - retry
                  approvalUrl:
                    anyOf:
                      - type: string
                        format: uri
                      - type: 'null'
                  command:
                    anyOf:
                      - type: string
                      - type: 'null'
                  expiresAt:
                    type: string
                    format: date-time
                    pattern: >-
                      ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                required:
                  - deployment
                  - kind
                  - approvalUrl
                  - command
                  - expiresAt
        '400':
          description: Invalid input.
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
        '401':
          description: Authentication required.
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
        '403':
          description: Owner or super-admin approval required.
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
        '404':
          description: Deployment or feature unavailable.
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
        '409':
          description: The deployment cannot accept this operation now.
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
        '429':
          description: Too many attempts.
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
        '503':
          description: No installer release is configured.
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
      security:
        - denApiKey: []
        - bearerAuth: []
components:
  securitySchemes:
    denApiKey:
      type: apiKey
      in: header
      name: x-api-key
      description: >-
        Organization API key passed as the `x-api-key` header. The raw key is
        the header value; do not prefix it with `Bearer`.
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: session-token
      description: >-
        Den session token passed as `Authorization: Bearer <session-token>` for
        user-authenticated Den routes. Not for API keys: send `den_` keys in the
        `x-api-key` header instead.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.