Skip to main content
POST
Press an Android key (KeyCode name).

Authorizations

Authorization
string
header
required

Pass a user JWT or a oag_ User API Key on the Authorization: Bearer <token> header. Both are validated by openapi-gateway against the Auth service.

Both credential types are user-scoped: every key (and every JWT) is bound to exactly one owner, and every route grants the caller full access to that owner's own resources. Cross-tenant access is denied by owner-ACL inside the handlers — there is no per-route scope vocabulary on this API.

Removed in v1.1.0: the legacy agents:* / tasks:* / files:* / instances:* scope set has been dropped together with the 403 insufficient_scope error. Existing oag_ keys automatically gain full owner-level access and do not need to be re-issued. SDK calls that previously passed scopes to createAPIKey should drop the argument. See the changelog at the bottom of this spec for the full migration note.

Path Parameters

id
string
required
Maximum string length: 128

Body

application/json
keys
string[]
required

Key name(s). One key = a key press; multiple keys = a hotkey combo (desktop). Mobile callers pass a single Android KeyCode.

Response

Standard { success, data } envelope; data is an ActionResult ({ ok: true }) acknowledging the device action completed. Device-reported failures map to 400 action_unsupported / invalid_param, 409 device_busy, 503 device_offline, or 504 service_timeout.

success
boolean
required
data
ActionResult · object
required

Generic acknowledgement that a mutating control action completed.