> ## Documentation Index
> Fetch the complete documentation index at: https://docs.codecobra.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# List Experimental Models

> The merged provider catalogs, for the composer's Custom… search.

Fireworks rows carry their upstream account path as the committable id;
DigitalOcean rows carry the ``do/``-prefixed id (see
services.do_catalog). The DO half only participates when the backend
holds a DO key, so a Fireworks-only deployment sees exactly the
pre-side-by-side behaviour, error text included.

Deliberately absent (404) rather than empty when the gate is off, so
production advertises no such surface at all.  Not tagged for the public
OpenAPI spec: this is a staging testing affordance, not product API.

A provider failure is reported as a 200 carrying ``error`` alongside
whatever the OTHER provider returned, rather than a 5xx.  The picker
keeps a free-text id field precisely so the panel stays usable when a
catalog cannot be read, and that fallback is only reachable if the
client can distinguish "catalog unavailable, carry on" from "the
request failed".



## OpenAPI

````yaml /openapi.json get /api/experimental/models
openapi: 3.1.0
info:
  description: >

    The CodeCobra API drives the same product the dashboard does: create a

    project, open a task against it, watch the agent work, and merge what it

    builds.


    ## Authenticating


    Send a personal API key as a bearer token on every request:


    ```

    Authorization: Bearer cc_your_key_here

    ```


    Mint a key from **Settings → API keys** in the dashboard. A key carries the

    full access of the user who created it, including every organization they

    belong to, so treat it like a password and point automations at a user with

    the access they actually need.


    ## What is not here


    A few dashboard actions are deliberately absent, because an API key should
    not

    be able to widen its own reach or start a flow only a browser can finish:


    * signing in, signing up, password resets and two-factor enrolment;

    * creating, listing or revoking API keys — a leaked key cannot mint another;

    * linking or unlinking a Google or GitHub identity;

    * connecting or disconnecting a GitHub App installation, which needs an
    OAuth
      round-trip in a browser to restore.

    Everything else the dashboard can do is in this reference.


    ## Conventions


    Identifiers are UUIDs. Timestamps are ISO 8601 in UTC. Money is a decimal

    string in USD. A failed request returns its reason in the `detail` field
    with

    a conventional status code: `401` for a missing or invalid key, `403` when
    the

    key's user lacks access to the object, `404` when it does not exist, and
    `429`

    when a rate limit is in play.
  title: CodeCobra API
  version: 1.0.0
servers: []
security:
  - ApiKeyBearer: []
tags:
  - description: >-
      The profile behind the API key, plus the app-wide configuration an
      integration needs before it can create anything: the Odoo versions on
      offer and the models a task may run on.
    name: Account
  - description: >-
      Projects are the unit of ownership. A project pins an Odoo version and
      edition, carries the GitHub repositories the agent works in, and holds
      every task underneath it. Deleting one removes its tasks, pods and stored
      files.
    name: Projects
  - description: >-
      A task is one conversation with the agent inside a project. These
      endpoints create tasks, drive the chat, stream the response, manage
      attachments, and start the pod the agent runs in.
    name: Tasks
  - description: >-
      The plan the agent writes before it builds, its revision history, and the
      files a task produces. Approving a plan is what releases the agent to
      start work.
    name: Plans & Artifacts
  - description: >-
      The pull requests a task opens: checking CI, asking the agent to fix a red
      build, choosing a merge target, and merging to a branch that deploys.
    name: Pull Requests & Deploys
  - description: >-
      Odoo databases a task can reach. Credentials are stored per project and
      activated per task; the probe endpoints validate a URL and login before
      anything is saved. Also covers the throwaway Odoo instance a task runs
      against.
    name: Odoo Connections
  - description: >-
      Shared accounts. An organization owns projects on behalf of its members
      and is billed as one entity.
    name: Organizations
  - description: >-
      Who belongs to an organization and at what role, and the invitations that
      put them there.
    name: Members & Invitations
  - description: >-
      Teams group members inside an organization and grant a whole group access
      to a set of projects at once.
    name: Teams
  - description: >-
      The GitHub App installations backing a personal or organization account,
      and the repositories and branches they expose to projects. Connecting and
      disconnecting GitHub needs a browser round-trip and stays in the
      dashboard.
    name: GitHub
  - description: Balance, payment methods, invoices and auto-reload for a personal account.
    name: Billing
  - description: >-
      The same billing operations for an organization, settled against the
      organization's balance rather than a member's.
    name: Organization Billing
  - description: >-
      What has been spent, broken down by task, project or organization, and
      exportable over a date range for billing reconciliation.
    name: Usage
paths:
  /api/experimental/models:
    get:
      tags:
        - Account
      summary: List Experimental Models
      description: |-
        The merged provider catalogs, for the composer's Custom… search.

        Fireworks rows carry their upstream account path as the committable id;
        DigitalOcean rows carry the ``do/``-prefixed id (see
        services.do_catalog). The DO half only participates when the backend
        holds a DO key, so a Fireworks-only deployment sees exactly the
        pre-side-by-side behaviour, error text included.

        Deliberately absent (404) rather than empty when the gate is off, so
        production advertises no such surface at all.  Not tagged for the public
        OpenAPI spec: this is a staging testing affordance, not product API.

        A provider failure is reported as a 200 carrying ``error`` alongside
        whatever the OTHER provider returned, rather than a 5xx.  The picker
        keeps a free-text id field precisely so the panel stays usable when a
        catalog cannot be read, and that fallback is only reachable if the
        client can distinguish "catalog unavailable, carry on" from "the
        request failed".
      operationId: list_experimental_models_api_experimental_models_get
      parameters:
        - in: query
          name: refresh
          required: false
          schema:
            default: false
            title: Refresh
            type: boolean
      responses:
        '200':
          content:
            application/json:
              schema: {}
          description: Successful Response
        '422':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
          description: Validation Error
      security:
        - HTTPBearer: []
components:
  schemas:
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          title: Detail
          type: array
      title: HTTPValidationError
      type: object
    ValidationError:
      properties:
        ctx:
          title: Context
          type: object
        input:
          title: Input
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          title: Location
          type: array
        msg:
          title: Message
          type: string
        type:
          title: Error Type
          type: string
      required:
        - loc
        - msg
        - type
      title: ValidationError
      type: object
  securitySchemes:
    ApiKeyBearer:
      description: A personal API key from Settings → API keys.
      scheme: bearer
      type: http

````