Reference
save_project
Keep the strip: save it as an editable ShotOps project with a URL to hand back.
What it does
- Writes
- Destructive
- Account required
The persistence step, and it happens when the user asks for it. It builds a structure and look record rather than pixels, so it is fast and never hits a render timeout, and it returns a URL the user opens in the web app. Omitting the project id creates a new project; passing one updates that project in place. Reach for it once someone wants the work preserved, shared, reused or kept editable — a request for images or a bundle is not that, and a render already told them nothing was saved and offered this call.
You can ask: “Save this Tidebook strip as a new project I can reopen later.”
Annotated destructive because passing an existing project id overwrites that project’s structure. Creating a new one is not destructive; the annotation covers the worst case, as the MCP spec asks.
Input
screenshotsarrayrequiredat least 1 itemat most 10 itemsScreenshots in App Store display order (1–10). Preferred common form: a FLAT array, where each entry becomes its own App Store panel, e.g. [{ "ref": "first" }, { "ref": "second" }]. Advanced multi-phone form: a NESTED array of slots, where several entries inside one slot are composited into that single panel, e.g. [[{ "ref": "left" }, { "ref": "right" }], [{ "ref": "third" }]]. Each screenshot entry is EITHER an inline base64 PNG string (capped at 3MB of image data — a full-resolution screenshot is 3-4MB and will NOT fit; use a ref for anything real), OR { "ref": "..." } from request_screenshot_upload, OR { "url": "https://..." }, OR (local stdio mode only) { "path": "/abs/or/relative/path.png" } to read a file straight off disk, OR { "locales": { "<locale>": <any of those> } } to vary that screenshot per App Store locale (missing locales fall back to the en-US variant). Prefer ref/url for real screenshots so the bytes never transit this conversation. NOTE: save_project does not render — it uses only each slot's SHAPE (phones per panel) and each entry's
name(source filename, for re-load matching). The image bytes are never fetched or stored, so pass the same entries you rendered with (esp. theirnames).each item
any
The published schema does not constrain this element, on purpose — a malformed entry comes back as a sentence instead of a stacked union error. What the server re-validates against is below.
panelPresetIdstringoptionalApp Store screenshot size. Default r69 (6.9″ iPhone, 1290×2796). iPhone sizes only — iPad is not rendered yet.
one of
r69r65r55outputsarrayoptionalat least 1 itemat most 2 itemsThe target DEVICES this project is for — iphone-6-9 (1290×2796) and/or iphone-6-5 (1242×2688), in the order they should be offered. On save_project this is saved ON the project (the same Output list the web app shows) and the first entry becomes the previewed size unless
panelPresetIdsays otherwise; on render_project it OVERRIDES the saved set for this call. Omit it and the project's saved outputs are used unchanged.each item
string
one of
iphone-6-9iphone-6-5lookobjectoptionalA ShotOps "look" — per-DEVICE styling + background, exactly as read_look returns it. Its shots[] give every screenshot/phone its own styling (including multiple phones in one panel); style.shotLook is one shared style for all. COMPOSES with
style: pass a look for the devices +style.captionsfor the words in ONE render. Validated — unknown keys are rejected (call describe_look for the full field catalog).schemanumberoptionalLook schema version. The server stamps it on every save (save_look); read_look returns it. Any input value is ignored — never set it yourself.
panelPresetIdstringoptionalCanvas size preset, e.g. r69 = 1290×2796. Default r69.
bgModestringoptionalOne gradient across the strip, or a flat colour per panel. Default gradient.
one of
gradientperPanelgradientStopsarrayoptionalat least 1 itemCanonical gradient stops — { color (hex), at (0–1 position) } — wins over gradientFrom/gradientTo/gradientDir when present. Read this back for the full stop list a Studio-authored look may carry; the trio below is only ever a two-stop summary.
each item
object
colorstringrequiredatnumberrequiredmin 0max 1
gradientAnglenumberoptionalCanonical gradient angle in degrees, clockwise from "to top" (CSS convention: 90 = right, 180 = down, the gradientDir:"vertical" equivalent). Paired with gradientStops.
gradientFromstringoptionalGradient start (hex) — a DERIVED mirror of gradientStops[0], re-derived from the stops on every render and reload. Setting it ALONE changes nothing: set gradientStops to change the backdrop. Default #1b1b2e.
gradientTostringoptionalGradient end (hex) — a DERIVED mirror of the last gradientStops entry, re-derived from the stops on every render and reload. Setting it ALONE changes nothing: set gradientStops to change the backdrop. Default #0a0a14.
gradientDirstringoptionalA DERIVED mirror of gradientAngle (nearest axis), re-derived on every render and reload. Setting it ALONE changes nothing: set gradientAngle to turn the gradient. Default vertical.
one of
horizontalverticalpanelColorsobjectoptionalPer-panel flat colours (mode perPanel), keyed by panel id.
shadowbooleanoptionalDrop shadow under the phones. Default true.
floorReflectionbooleanoptionalFlipped, faded floor reflection under each phone. Default false.
panelBackgroundsobjectoptionalPer-frame background overrides keyed by panel id (web-authored; agents rarely set these).
captionStylesobjectoptionalPer-panel caption STYLE arrays keyed by panel id (styling only, no words — for caption text pass style.captions).
shotsarrayoptionalat most 60 itemsOne entry per SCREENSHOT/DEVICE, flattened in panel order. Each entry has its OWN
look. For screenshots:[[left,right]], pass two shots with the SAME panelId ("panel-1") to give the two devices different colours/materials/angles. This is how a look varies devices; style.shotLook cannot.each item
object
panelIdstringoptionalPanel containing this screenshot/device. Panels are panel-1…panel-N in slot order; REPEAT the same panelId for multiple devices in one panel. A saved look’s own ids are remapped by ordinal.
lookobjectoptionalThis individual screenshot/device’s styling — the SAME fields as style.shotLook.
anglestringoptionalCamera preset. Default front.
one of
frontleftrightcameraPosone of 2 shapesoptionalManual camera position override; null/omit = use the angle preset.
1
xxnumberrequiredynumberrequiredznumberrequired
2
nullrollstring or numberoptional-45–45° clock-hand tilt. Default 0.
phoneHeightstring or numberoptional-45–45° clock-hand tilt. Default 0.
hOffsetstring or numberoptional-45–45° clock-hand tilt. Default 0.
vOffsetstring or numberoptional-45–45° clock-hand tilt. Default 0.
materialstringoptionalDevice body. Default real.
one of
realclaycolorwaystringoptionalBody colour (material "real"). Default silver. These are finish SLOTS — each device binds its own real finish (silver = iPhone Silver / Pixel Moonstone). "green" is Pixel-only (Jade); other devices fall back to their first finish.
one of
orangebluesilvergreencustomcustomColorstringoptionalHex body colour when colorway is "custom".
finishstring or numberoptional-45–45° clock-hand tilt. Default 0.
clearcoatstring or numberoptional-45–45° clock-hand tilt. Default 0.
clayTonestringoptionalClay tone (material "clay"). Default grey.
one of
greywhitecharcoalcustomclayCustomstringoptionalHex clay colour when clayTone is "custom".
flatScreenbooleanoptionalRender the screen flat (no curvature). Default false.
glarebooleanoptionalScreen glare. Default false.
lightingbooleanoptionalScene lighting. Default true.
reflectionsbooleanoptionalBody reflections. Default false.
clipToFramebooleanoptionalClip this complete device composite to its owning frame. Default false (overflow allowed).
styleobjectoptionalStructured styling — the discoverable path (call describe_look for the full field catalog + defaults).
layoutis the fastest way in: one named composition that settles the headline region and the device placement together, with your explicit fields still winning over it. COMPOSES withlook: pass BOTH to get per-device styling from thelookAND captions fromstyle.captionsin ONE render (every real App Store strip). When alookis also given it supplies the devices + background, sostyle.shotLook/style.backgroundare ignored (a note says so) — usestyleforcaptionsthen. Alone,stylestyles every phone identically + captions. Also composes withuseSavedLook/version.layoutstringoptionalPanel COMPOSITION template — sets the headline’s reserved region and the device’s placement, camera pose, and roll in one choice. "standard" — Headline on top, whole device below it, nothing cropped. The safe default. Reserves 2 headline lines (~36 characters). Character: [safe]. "bleed" — Room for a longer headline, device running off the bottom edge. What the market looks like. Reserves 4 headline lines (~72 characters). Character: [conventional]. "top-bleed" — Device running off the TOP edge, headline underneath it. Inverts the usual reading order. Reserves 4 headline lines (~72 characters). Character: [expressive]. PRECEDENCE: the template expands FIRST into shotLook.phoneHeight/shotLook.hOffset/shotLook.vOffset/shotLook.angle/shotLook.cameraPos/shotLook.roll and captions[].sizePt/captions[].maxWidth/captions[].reserveLines/captions[].band, and THEN any of those fields you pass EXPLICITLY overrides it — so { layout: "bleed", shotLook: { vOffset: "45" } } renders bleed seated at 45, not at the template’s 38. That is how you say "bleed, but a bit lower" without the template silently winning. The reserved region is held at FULL SIZE whether or not the headline fills it, which is what makes every panel in a swiped set land on the same line. Nothing stores the template id: it is discarded at expansion, so a saved project and read_look carry only the expanded values.
one of
standardbleedtop-bleedshotLookobjectoptionalThis individual screenshot/device’s styling — the SAME fields as style.shotLook.
anglestringoptionalCamera preset. Default front.
one of
frontleftrightcameraPosone of 2 shapesoptionalManual camera position override; null/omit = use the angle preset.
1
xxnumberrequiredynumberrequiredznumberrequired
2
nullrollstring or numberoptional-45–45° clock-hand tilt. Default 0.
phoneHeightstring or numberoptional-45–45° clock-hand tilt. Default 0.
hOffsetstring or numberoptional-45–45° clock-hand tilt. Default 0.
vOffsetstring or numberoptional-45–45° clock-hand tilt. Default 0.
materialstringoptionalDevice body. Default real.
one of
realclaycolorwaystringoptionalBody colour (material "real"). Default silver. These are finish SLOTS — each device binds its own real finish (silver = iPhone Silver / Pixel Moonstone). "green" is Pixel-only (Jade); other devices fall back to their first finish.
one of
orangebluesilvergreencustomcustomColorstringoptionalHex body colour when colorway is "custom".
finishstring or numberoptional-45–45° clock-hand tilt. Default 0.
clearcoatstring or numberoptional-45–45° clock-hand tilt. Default 0.
clayTonestringoptionalClay tone (material "clay"). Default grey.
one of
greywhitecharcoalcustomclayCustomstringoptionalHex clay colour when clayTone is "custom".
flatScreenbooleanoptionalRender the screen flat (no curvature). Default false.
glarebooleanoptionalScreen glare. Default false.
lightingbooleanoptionalScene lighting. Default true.
reflectionsbooleanoptionalBody reflections. Default false.
clipToFramebooleanoptionalClip this complete device composite to its owning frame. Default false (overflow allowed).
backgroundobjectoptionalmodestringoptionalOne gradient across the strip, or a flat colour per panel.
one of
gradientperPanelstopsarrayoptionalat least 1 itemGradient colour stops, in order along the gradient line — { color (hex), at (0–1 position; 0 = line start, 1 = line end) }. Two stops is the classic top/bottom gradient, more make a multi-colour sweep, one stop is a solid fill. Default a two-stop navy gradient: [{color:"#1b1b2e",at:0},{color:"#0a0a14",at:1}].
each item
object
colorstringrequiredatnumberrequiredmin 0max 1
anglenumberoptionalGradient angle in degrees, clockwise from "to top" — CSS
linear-gradient()convention: 90 = to right, 180 = to bottom (the old "vertical" default, and this field’s own default), 270 = to left. Any value folds into 0–360.panelColorsarrayoptionalat most 10 itemsPer-panel flat colours (mode "perPanel"), one entry per slot in order; null = default.
each item
string or null
shadowbooleanoptionalDrop shadow under the phones. Default true.
floorReflectionbooleanoptionalFlipped, faded floor reflection under each phone. Default false.
captionsarrayoptionalat most 10 itemsOne entry PER PANEL in slot order; null = no caption on that panel. An entry is EITHER a single caption object OR an array of caption layers (stacked, in order) on that panel. Alongside a
look, an entry is a DELTA: every style field you set wins, every field you leave out keeps the look’s styling for that panel and layer — which is what lets you re-render alayout.correctedLookwithout restating your captions.each item
one of 2 shapes
1
one of 2 shapes1
objectfontIdstringoptionalBundled font. Default inter.
one of
intermanropepoppinsfrauncesspace-grotesksizePtnumberoptionalgreater than 0Font size in iOS points (preset-independent), 20–120. Default 32. Outside that range it is clamped to it and the response says so.
colorstringoptionalText colour (hex). Default FFFFFF.
alignstringoptionalDefault center.
one of
leftcenterrightanchorobjectoptionalNormalized 0–1 position of the caption on the panel. Default {x:0.5, y:0.06}.
xnumberoptionalmin 0max 1ynumberoptionalmin 0max 1
maxWidthnumberoptionalgreater than 0Wrap width as a fraction of the panel, 0.1–1. Default 0.86. Outside that range it is clamped to it and the response says so.
reserveLinesintegeroptionalmin 1max 8How many lines of headline room to HOLD, whether or not the text fills it. A shorter headline is centred in the reserved space rather than leaving all the slack beneath it, and the space is held so every panel in the strip lands on the same line. Omit to let the caption be exactly as tall as its text. Set for you by style.layout.
bandstringoptionalPut this caption in the BOTTOM band, growing upward from the lower margin, instead of the default top band. This is how a headline sits UNDER the device (see the top-bleed layout). The caption stays auto-placed — it still reflows and still stacks; use this rather than pinning an anchor, which would freeze it.
one of
bottombandInsetnumberoptionalmin 0max 0.5Inset of the auto caption band from its own panel edge, as a 0–0.5 fraction of panel height. The top band measures down; the bottom band mirrors it upward. Default 0.06.
lineHeightnumberoptionalmin 0.5max 3Line spacing as a multiple of font size, 0.5–3. Default 1.2.
bandCenternumberoptionalmin 0max 1Horizontal reference of the auto caption block as a 0–1 fraction of panel width. Text alignment decides which edge sits there. Default 0.5.
textstringoptionalat most 200 charactersThe headline — per-RENDER input, never stored in a look.
subtitlestringoptionalat most 300 charactersOptional subtitle under the headline — also per-render input.
2
arrayeach item
object
fontIdstringoptionalBundled font. Default inter.
one of
intermanropepoppinsfrauncesspace-grotesksizePtnumberoptionalgreater than 0Font size in iOS points (preset-independent), 20–120. Default 32. Outside that range it is clamped to it and the response says so.
colorstringoptionalText colour (hex). Default FFFFFF.
alignstringoptionalDefault center.
one of
leftcenterrightanchorobjectoptionalNormalized 0–1 position of the caption on the panel. Default {x:0.5, y:0.06}.
xnumberoptionalmin 0max 1ynumberoptionalmin 0max 1
maxWidthnumberoptionalgreater than 0Wrap width as a fraction of the panel, 0.1–1. Default 0.86. Outside that range it is clamped to it and the response says so.
reserveLinesintegeroptionalmin 1max 8How many lines of headline room to HOLD, whether or not the text fills it. A shorter headline is centred in the reserved space rather than leaving all the slack beneath it, and the space is held so every panel in the strip lands on the same line. Omit to let the caption be exactly as tall as its text. Set for you by style.layout.
bandstringoptionalPut this caption in the BOTTOM band, growing upward from the lower margin, instead of the default top band. This is how a headline sits UNDER the device (see the top-bleed layout). The caption stays auto-placed — it still reflows and still stacks; use this rather than pinning an anchor, which would freeze it.
one of
bottombandInsetnumberoptionalmin 0max 0.5Inset of the auto caption band from its own panel edge, as a 0–0.5 fraction of panel height. The top band measures down; the bottom band mirrors it upward. Default 0.06.
lineHeightnumberoptionalmin 0.5max 3Line spacing as a multiple of font size, 0.5–3. Default 1.2.
bandCenternumberoptionalmin 0max 1Horizontal reference of the auto caption block as a 0–1 fraction of panel width. Text alignment decides which edge sits there. Default 0.5.
textstringoptionalat most 200 charactersThe headline — per-RENDER input, never stored in a look.
subtitlestringoptionalat most 300 charactersOptional subtitle under the headline — also per-render input.
2
null
useSavedLookbooleanoptionalIf true, style the strip with the project's saved look (ignored when
look/styleis given).projectstringoptionalat least 1 characterWhich ShotOps project to target: its id (as returned by read_look/save_project), OR its NAME as the user says it — matched exactly, ignoring case and surrounding spaces. Omit = your most recently edited project. A name that matches none or several is refused with the account's projects listed, never resolved by guessing.
versionintegeroptionalmin 1Render a specific saved look version of the project (implies the saved look). Omit = the project's HELD version if one is held (hold_look), else the latest saved look.
localestringoptionalApp Store locale, e.g. "de-DE" (default en-US). Labels the render, selects which { "locales": … } screenshot variants render, and, for emit_bundle, selects the fastlane screenshots folder. Does not select caption text — pass the copy for this locale yourself via
style.captions[].text(see the README'scaptions.<locale>.jsonconvention).projectNamestringoptionalName for the created project (when createProject makes a new one). Default "ShotOps render".
sourceDirstringoptionalAdvanced: the on-disk folder these screenshots were read from (only meaningful when they came from local { path } entries on the SAME machine). When set, the saved project remembers this folder as its screen source (kind: "local-path") instead of just filenames. Used by the local stdio bridge — most callers should omit it.
What the server actually accepts
The published schema above deliberately accepts a wider shape for screenshots, so a malformed entry comes back as a sentence rather than a stack of union errors. The server re-validates against these shapes and refuses anything else.
screenshotsone of 2 shapesrequiredScreenshots in App Store display order (1–10). Preferred common form: a FLAT array, where each entry becomes its own App Store panel, e.g. [{ "ref": "first" }, { "ref": "second" }]. Advanced multi-phone form: a NESTED array of slots, where several entries inside one slot are composited into that single panel, e.g. [[{ "ref": "left" }, { "ref": "right" }], [{ "ref": "third" }]]. Each screenshot entry is EITHER an inline base64 PNG string (capped at 3MB of image data — a full-resolution screenshot is 3-4MB and will NOT fit; use a ref for anything real), OR { "ref": "..." } from request_screenshot_upload, OR { "url": "https://..." }, OR (local stdio mode only) { "path": "/abs/or/relative/path.png" } to read a file straight off disk, OR { "locales": { "<locale>": <any of those> } } to vary that screenshot per App Store locale (missing locales fall back to the en-US variant). Prefer ref/url for real screenshots so the bytes never transit this conversation. NOTE: save_project does not render — it uses only each slot's SHAPE (phones per panel) and each entry's
name(source filename, for re-load matching). The image bytes are never fetched or stored, so pass the same entries you rendered with (esp. theirnames).1
arrayPreferred: one screenshot entry per App Store panel, in display order.
each item
one of 5 shapes
1
stringInline base64-encoded PNG (no "data:" prefix). Capped at 3MB of image data — a real full-resolution screenshot is 3-4MB and will NOT fit. Use request_screenshot_upload and pass { ref } instead; inline is for thumbnails and tests.
2
refA ref returned by request_screenshot_upload — resolved server-side, never re-sent inline.
refstringrequiredat least 1 characternamestringoptionalat most 200 charactersThe screenshot's original filename (e.g. "03_statistics.png"). Pass it so that, if this render is saved as a project, the user's own screenshots folder re-loads exactly this file by name. Optional if the ref already carries a name (from request_screenshot_upload({ names })); omit entirely and the record falls back to a positional name (screen-N.png).
3
urlAn https URL to a PNG or JPEG — fetched server-side, converted to PNG when needed (no redirects, ~20MB cap).
urlstringrequiredat least 1 characternamestringoptionalat most 200 charactersThe screenshot's original filename (e.g. "03_statistics.png"). Pass it so that, if this render is saved as a project, the user's own screenshots folder re-loads exactly this file by name. Optional if the ref already carries a name (from request_screenshot_upload({ names })); omit entirely and the record falls back to a positional name (screen-N.png).
4
pathA local filesystem path to a PNG, read straight off disk — ONLY available over the local stdio server (npx shotops-mcp); the hosted server rejects this entry shape.
pathstringrequiredat least 1 characternamestringoptionalat most 200 charactersThe screenshot's original filename (e.g. "03_statistics.png"). Pass it so that, if this render is saved as a project, the user's own screenshots folder re-loads exactly this file by name. Optional if the ref already carries a name (from request_screenshot_upload({ names })); omit entirely and the record falls back to a positional name (screen-N.png).
5
localesPer-locale variants of ONE screenshot: { "locales": { "en-US": <entry>, "de-DE": <entry> } } (each variant is an inline base64 / ref / url / path entry). render_strip picks the top-level
locale's variant; emit_bundle withlocalesrenders/packages every listed locale. A locale with no variant of its own falls back to the en-US variant (else the first declared), so you can localize only some screenshots.localesobjectrequired
2
arrayAdvanced: one nested slot per panel; put several screenshot entries in a slot for a multi-phone panel.
each item
array
One App Store slot: 1–6 screenshots. Several entries = several phones composited into that one slot.
each item
one of 5 shapes
1
stringInline base64-encoded PNG (no "data:" prefix). Capped at 3MB of image data — a real full-resolution screenshot is 3-4MB and will NOT fit. Use request_screenshot_upload and pass { ref } instead; inline is for thumbnails and tests.
2
refA ref returned by request_screenshot_upload — resolved server-side, never re-sent inline.
refstringrequiredat least 1 characternamestringoptionalat most 200 charactersThe screenshot's original filename (e.g. "03_statistics.png"). Pass it so that, if this render is saved as a project, the user's own screenshots folder re-loads exactly this file by name. Optional if the ref already carries a name (from request_screenshot_upload({ names })); omit entirely and the record falls back to a positional name (screen-N.png).
3
urlAn https URL to a PNG or JPEG — fetched server-side, converted to PNG when needed (no redirects, ~20MB cap).
urlstringrequiredat least 1 characternamestringoptionalat most 200 charactersThe screenshot's original filename (e.g. "03_statistics.png"). Pass it so that, if this render is saved as a project, the user's own screenshots folder re-loads exactly this file by name. Optional if the ref already carries a name (from request_screenshot_upload({ names })); omit entirely and the record falls back to a positional name (screen-N.png).
4
pathA local filesystem path to a PNG, read straight off disk — ONLY available over the local stdio server (npx shotops-mcp); the hosted server rejects this entry shape.
pathstringrequiredat least 1 characternamestringoptionalat most 200 charactersThe screenshot's original filename (e.g. "03_statistics.png"). Pass it so that, if this render is saved as a project, the user's own screenshots folder re-loads exactly this file by name. Optional if the ref already carries a name (from request_screenshot_upload({ names })); omit entirely and the record falls back to a positional name (screen-N.png).
5
localesPer-locale variants of ONE screenshot: { "locales": { "en-US": <entry>, "de-DE": <entry> } } (each variant is an inline base64 / ref / url / path entry). render_strip picks the top-level
locale's variant; emit_bundle withlocalesrenders/packages every listed locale. A locale with no variant of its own falls back to the en-US variant (else the first declared), so you can localize only some screenshots.localesobjectrequired
Result
okbooleanoptionalprojectIdstringoptionalstatusstringoptionalalways "pending_claim"ownershipstringoptionalalways "pending"claimIdstringoptionalopenUrlstringoptionalformat uricountnumberoptionalpanelPresetIdstringoptionallocalestringoptionalmessagestringoptionaloutputsarrayoptionaleach item
string
notestringoptionalFree-text advisories about THIS call, joined into one string. Written when the server did something you did not literally ask for or could not have known: a look/version fallback, an output-mode downgrade, a device this server cannot render, a
style.shotLookalookoverrode, or placement set by hand where astyle.layouttemplate would have produced the same composition. Never an error — the call succeeded. Read it, and act on it next call.disclosureobjectoptionalStated because this call moved caller bytes into ShotOps storage. Relay it before or with the result; do not paraphrase the retention window.
movesstringrequiredThe bytes that left the caller’s control, in plain words.
whystringrequiredWhat the move buys — never a restatement of the mechanism.
retentionDaysintegerrequiredgreater than 0How long ShotOps keeps it without an explicit retaining action. Read from the retention policy, never typed.
retainedBystringrequiredThe explicit action that keeps it past that window.
statementstringrequiredThe same four facts as one sentence, safe to relay verbatim.
contractobjectoptionalThe versioned ShotOps result contract (#662): what ran, where, what it changed, what it cost, what it produced and — on a refusal — a typed failure over a closed code catalog. Structured content is authoritative; the prose beside it is a rendering of this block.
contractVersionstringrequiredThe version of THIS envelope, REPORTED. Compare it against the version you were written for. There is no version negotiation: no tool accepts a requested version, so this is never a refusal — it moves only when a field changes meaning, and additive fields never move it.
statusstringrequiredone of
succeededpartialfailedrefusedacceptedqueuedrunningcancel_requestedcancelledterminalbooleanrequiredfalse ⟹ this operation is still running and will be reported again (#666).
operationobjectrequiredidstringrequiredIdentity for THIS call, unique per invocation. Quote it in a bug report.
toolstringrequiredThe registered tool name that produced this result.
kindstringrequiredone of
renderbundlereadmutateuploaddeletestatusdurableobjectoptional#666 domain handle for addressable long-running work. Absent from synchronous calls.
operationIdstringrequiredpollWithstringoptional
executionobjectrequiredlocationstringrequiredWhere the work RAN.
localis the caller’s own machine over stdio.one of
localhostedinputModesarrayrequiredEvery way this door accepts screenshots and assets.
each item
string
one of
inline_base64stored_refremote_urllocal_pathproject_storeddeliveryModesarrayrequiredEvery way this door can hand a result back.
each item
string
one of
inline_base64signed_urllocal_pathshare_link
effectsobjectrequiredWhat this call DID to the world, independent of what it returned. Every flag is stated on every result, false included: an absent flag would be indistinguishable from an effect nobody thought to declare.
networkFetchbooleanrequiredThis call fetched bytes from a host neither ShotOps nor the caller controls.
uploadbooleanrequiredCaller bytes were uploaded into ShotOps storage.
retainedStoragebooleanrequiredSomething survives this call in ShotOps storage.
projectMutationbooleanrequiredA saved project or its look history changed.
publicationbooleanrequiredSomething became reachable outside the account — a share link.
deletionbooleanrequiredSomething was permanently removed.
costobjectrequiredunitstringrequiredalways "credit"Public cloud credits — the same unit every ShotOps surface quotes.
modelstringrequiredHow this connection pays.
unmeteredis local stdio, which renders on the caller’s own machine;anonymous_allowanceis the unsigned hosted taste.one of
meteredanonymous_allowanceunmeteredestimatednumberoptionalWhat the call was expected to cost, before it ran.
reservednumberoptionalHeld against the wallet for the duration of the call (#666).
releasednumberoptionalGiven back — an unused reservation or a refund after a post-charge failure (#666).
settlednumberoptionalActually taken. Absent when nothing was charged.
balanceAfternumberoptionalThe wallet’s public cloud credit balance once this call settled.
refillAtstringoptionalISO 8601. When the wallet is next topped up; absent when none is scheduled.
progressobjectoptionalPersisted monotonic durable-operation progress. Never inferred from transient render metadata. Relay
panelsCompleted/panelsTotaland the estimate to the waiting user; the item counters are internal bookkeeping and do not match what they asked for.completedintegerrequiredmin 0Internal scheduling items done — panels PLUS the bundle and result items. Do not quote this to a person.
totalintegerrequiredmin 0Internal scheduling items in total. Larger than the panel count.
panelsCompletedintegeroptionalmin 0Panels finished, in the unit the caller asked in. THIS is the number to report.
panelsTotalintegeroptionalmin 0Panels this operation will produce — the count the user asked for.
attemptintegerrequiredmin 0heartbeatAtstring or nulloptionalestimatedRemainingSecondsnumberoptionalmin 0Rough seconds of rendering left, from this operation’s own measured pace once a panel has landed. An estimate, not a deadline — say “about”. Absent when nothing is left to render.
resolvedInputobjectoptional#661 — what the server actually resolved the request to, before any pixel was produced.
snapshotIdstringoptionalpsi_+ the first 32 hex of the fingerprint. Quote it in a bug report.fingerprintstringoptionalsha256 over every resolved fact. Equal fingerprints ⟹ equal production input.
sourcesarrayoptionalOne entry per source cell, resolved or not.
slotis the cell the bytes came FROM — a shot id and coordinate on a saved project, an ordered slot label on a direct render. Never a filename, a ref or a URL.originis absent exactly whenstatusis notresolved: there is nothing the cell came from.each item
object
slotstringrequiredstatusstringrequiredone of
resolvedmissingambiguousoriginstringoptionalone of
inline_base64stored_refremote_urllocal_pathproject_stored
defaultsAppliedarrayoptionalWhat the server chose because the caller said nothing.
each item
string
overridesarrayoptionalWhat the caller said that changed the outcome.
each item
string
readinessobjectoptional#665 — the readiness verdict and any waiver receipt.
statestringoptionalblocked⟹ nothing was delivered.ready_with_findings⟹ delivered, and here is what to know.one of
readyready_with_findingswaivedblockedpolicyVersionstringoptionalThe readiness policy this verdict was computed under. A waiver granted under another one is rejected.
findingsarrayoptionalEvery finding, with
code,waivableanddigest. A waiver names one id AND its digest; there is no wildcard and no code-level waiver.each item
object
idstringrequiredrf_+ 24 hex. Quote it in a waiver.severitystringrequiredone of
infowarnblockmessagestringrequiredtargetobjectrequiredThe exact shot, panel, locale, output or frames this finding is about.
shotIdstringoptionalpanelIndexnumberoptionallocalestringoptionaloutputstringoptionalcaptionLayernumberoptionalframesarrayoptionaleach item
number
evidenceobjectrequiredBounded redacted facts used to derive the finding and its digest.
waiversarrayoptionalThe waivers this call ACCEPTED. Pass these objects back verbatim to reuse them; a rebuilt one is rejected.
each item
object
findingIdstringrequiredfindingDigeststringrequiredpolicyVersionstringrequiredwaivedBystringrequiredwaivedAtstringrequiredcodestringrequiredone of
source_identity_ambiguousoutput_unsupportedoutput_omittedlook_exact_unavailableno_panelspanel_invalid_pngpanel_dimensions_invalidrenderer_failedinput_changed_during_runpanel_source_emptylocale_source_fallbackdevice_source_fallbackcaption_inheritedcaption_locale_fallbacklook_source_fallbackcaption_device_collisioncaption_caption_collisiondevice_device_collisioncaption_legibility_unresolvedscope_filteredlocale_not_live_on_applelook_hold_inactivecaption_text_emptyreasonstringoptional
artifactsarrayoptionaleach item
object
idstringrequiredThe opaque asset id from the custody registry (#663) — or, for
kind: "share", the link’s own token. Never a storage path, and never a signed URL.kindstringrequiredone of
panelbundlescreenshotshareprojectdeliveryobjectrequiredmodestringrequiredone of
inline_base64signed_urllocal_pathshare_linkurlstringoptionalTHE ONE FIELD a signed URL may appear in. Nothing else in this envelope carries one.
expiresAtstringoptionalISO 8601, when the grant above stops working.
bytesnumberoptionalretainedUntilstringoptionalISO 8601, when ShotOps stops keeping the artifact itself.
failureobjectoptionalPresent exactly when
statusisfailedorrefused.codestringrequiredThe closed failure code. Branch on this, never on the sentence.
one of
invalid_inputunsupported_inputproject_not_foundproject_ambiguousno_projectsversion_not_foundresolution_incompletereadiness_requiredreadiness_unmetasset_not_foundasset_in_useauthentication_requiredplan_requiredtrial_choice_requiredquota_exhaustedanonymous_limit_reachedcapability_deniedbilling_unavailablerender_failedstorage_failedpersistence_failedupstream_unavailablepayload_too_largerate_limitedoperation_not_foundidempotency_conflictoperation_unavailableoperation_not_readycontract_version_unsupportedinternal_errorphasestringrequiredHow far the call got.
inputandauthorizationguarantee nothing was rendered, stored, written or charged.one of
inputauthorizationresolutionreservationexecutiondeliverypersistenceretryablebooleanrequiredtrue ⟹ the identical call may succeed later with nothing changed.
nextActionstringrequiredThe one move that resolves this, machine-readable.
one of
nonefix_inputchoose_projectupload_assetsreduce_scopesign_inchoose_planupgrade_planretrywait_and_retrypoll_operationupgrade_clientcontact_supportdetailsobjectoptionalBounded, redacted, code-specific facts (the offending field name, the candidate project ids, the required plan). Never a credential, a signed URL or screenshot bytes.
Example
That request maps to this call:
{
"name": "save_project",
"arguments": {
"screenshots": [
{
"ref": "uploads/you/tidebook/01-today.png",
"name": "01-today.png"
},
{
"ref": "uploads/you/tidebook/02-forecast.png",
"name": "02-forecast.png"
},
{
"ref": "uploads/you/tidebook/03-spots.png",
"name": "03-spots.png"
}
],
"projectName": "Tidebook 2.4 launch"
}
}A project id and an openUrl to give the user. From an unsigned local server it returns an explicit seven-day pending claim instead — the user owns the project once they open the URL and sign in.
Access and cost
- Needs an account on the hosted server. On local stdio an unsigned save is allowed and becomes a pending claim.
- Free, on both doors. Saving spends no cloud credits and renders nothing.
- An unsigned local save is the one local path that uploads pixels — the raw PNGs go to temporary private claim storage so the user can claim them. Ordinary local rendering and exporting upload nothing.
- A Free account may own 2 projects. Pro is unlimited.
When it refuses
- The reply says the project allowance is used up.
- Delete a project in the web app, or upgrade. Nothing was saved.
- A pending claim expires unclaimed.
- The seven-day window closed and the temporary upload is gone. Save again and open the URL this time.
- You passed a project id and it updated something the user did not expect.
- Only pass an id when the user explicitly says the work belongs in that project. Omit it and a new project is created instead.
Where this fits
What the agent is told
The title and description the server publishes on tools/list — this is the copy a model chooses between, reproduced verbatim.
Save as editable project
Let the user keep the strip: save it as an editable ShotOps project they can open in the web app, refine by hand, and have re-rendered later by render_project. Returns an openUrl to hand back and, when already authenticated, a projectId. Unsigned local stdio instead returns an explicit pending claim; the user owns it after opening the URL and signing in. No panel PNGs are returned. Fast, and it does NOT render: it builds a byte-free structure + look record, so no panel bytes are returned and it never hits the render timeout. `outputs` names the device sizes the project targets; an existing `project` id updates that project in place, omitting it creates a new one. CALL IT WHEN THE USER ASKS FOR PERSISTENCE, not as the closing step of every job: this is the door for someone who said they want to keep, share, reuse or keep editing the work. A request for images, full-resolution panels or a bundle is not that, and neither is silence — a render already told them nothing was saved and offered this call. Pass `project` only when they named an existing project as the target; never infer one from the most recently edited. An UNSIGNED local save is the one local path that moves bytes: it stages the raw PNGs in private claim storage so the claimed project reopens whole, and its result carries a `disclosure` block naming what moved, why, how long it is kept and what retains it. Ordinary local render/export never uploads.