Registry · Capabilities · huggingface.co
Capability registry
What huggingface.co declares an agent can do
Measured 2026-10-07 03:18 UTC from the declarations the site publishes (record ukp8nsr35c). Each capability is shown as declared, under the policy class that decides whether anything may call it, beside what a call observed.
Declared versus observed
| Capability | Policy class | Declared | Observed |
|---|---|---|---|
| https://huggingface.co api · https://huggingface.co | Metadata never called automatically | an API the catalog lists; its operations are in its own description auth: unknown | not attempted metadata: describes a surface, is not itself an action |
| GET /api/notifications openapi · GET · https://huggingface.co/api/notifications | External communication never called automatically | its name contains “notifications” auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/notifications openapi · DELETE · https://huggingface.co/api/notifications | External communication never called automatically | its name contains “notifications” auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/notifications/mark-as-read openapi · POST · https://huggingface.co/api/notifications/mark-as-read | External communication never called automatically | its name contains “notifications” auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/credentials/revoke openapi · POST · https://huggingface.co/api/credentials/revoke | Identity and accounts never called automatically | its name contains “credentials” auth: none · required inputs: 0 | not attempted classed identity_or_account: only read-only public actions are ever called |
| GET /api/settings/mcp openapi · GET · https://huggingface.co/api/settings/mcp | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| PATCH /api/settings/notifications openapi · PATCH · https://huggingface.co/api/settings/notifications | External communication never called automatically | its name contains “notifications” auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| PATCH /api/settings/watch openapi · PATCH · https://huggingface.co/api/settings/watch | Unknown never called automatically | PATCH with no declared reversibility auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/settings/webhooks openapi · GET · https://huggingface.co/api/settings/webhooks | External communication never called automatically | its name contains “webhooks” auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/settings/webhooks openapi · POST · https://huggingface.co/api/settings/webhooks | External communication never called automatically | its name contains “webhooks” auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/settings/webhooks/{webhookId} openapi · GET · https://huggingface.co/api/settings/webhooks/{webhookId} | External communication never called automatically | its name contains “webhooks” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/settings/webhooks/{webhookId} openapi · POST · https://huggingface.co/api/settings/webhooks/{webhookId} | External communication never called automatically | its name contains “webhooks” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/settings/webhooks/{webhookId} openapi · DELETE · https://huggingface.co/api/settings/webhooks/{webhookId} | External communication never called automatically | its name contains “webhooks” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/settings/webhooks/{webhookId}/{action} openapi · POST · https://huggingface.co/api/settings/webhooks/{webhookId}/{action} | External communication never called automatically | its name contains “webhooks” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/settings/webhooks/{webhookId}/replay/{logId} openapi · POST · https://huggingface.co/api/settings/webhooks/{webhookId}/replay/{logId} | External communication never called automatically | its name contains “webhooks” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/settings/papers/claim openapi · POST · https://huggingface.co/api/settings/papers/claim | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/settings/inference-providers openapi · POST · https://huggingface.co/api/settings/inference-providers | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/settings/inference-providers/api-key openapi · POST · https://huggingface.co/api/settings/inference-providers/api-key | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| PUT /api/settings/inference-providers/default-billing-entity openapi · PUT · https://huggingface.co/api/settings/inference-providers/default-billing-entity | Financial never called automatically | its name contains “billing” auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| PUT /api/settings/inference-providers/usage-limits openapi · PUT · https://huggingface.co/api/settings/inference-providers/usage-limits | Unknown never called automatically | PUT with no declared reversibility auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/settings/repositories openapi · GET · https://huggingface.co/api/settings/repositories | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/settings/tokens openapi · GET · https://huggingface.co/api/organizations/{name}/settings/tokens | Identity and accounts never called automatically | its name contains “tokens” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/organizations/{name}/settings/tokens/{tokenId}/revoke openapi · POST · https://huggingface.co/api/organizations/{name}/settings/tokens/{tokenId}/revoke | Identity and accounts never called automatically | its name contains “tokens” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/settings/repositories openapi · GET · https://huggingface.co/api/organizations/{name}/settings/repositories | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| PUT /api/organizations/{name}/settings/sso/credentials openapi · PUT · https://huggingface.co/api/organizations/{name}/settings/sso/credentials | Identity and accounts never called automatically | its name contains “credentials” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/audit-log/export openapi · GET · https://huggingface.co/api/organizations/{name}/audit-log/export | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/resource-groups/{resourceGroupId} openapi · GET · https://huggingface.co/api/organizations/{name}/resource-groups/{resourceGroupId} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| PATCH /api/organizations/{name}/resource-groups/{resourceGroupId} openapi · PATCH · https://huggingface.co/api/organizations/{name}/resource-groups/{resourceGroupId} | Unknown never called automatically | PATCH with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/organizations/{name}/resource-groups/{resourceGroupId} openapi · DELETE · https://huggingface.co/api/organizations/{name}/resource-groups/{resourceGroupId} | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/organizations/{name}/resource-groups/{resourceGroupId}/settings openapi · POST · https://huggingface.co/api/organizations/{name}/resource-groups/{resourceGroupId}/settings | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/organizations/{name}/resource-groups/{resourceGroupId}/users openapi · POST · https://huggingface.co/api/organizations/{name}/resource-groups/{resourceGroupId}/users | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| PATCH /api/organizations/{name}/resource-groups/{resourceGroupId}/users/{username} openapi · PATCH · https://huggingface.co/api/organizations/{name}/resource-groups/{resourceGroupId}/users/{username} | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/organizations/{name}/resource-groups/{resourceGroupId}/users/{username} openapi · DELETE · https://huggingface.co/api/organizations/{name}/resource-groups/{resourceGroupId}/users/{username} | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/resource-groups openapi · GET · https://huggingface.co/api/organizations/{name}/resource-groups | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/organizations/{name}/resource-groups openapi · POST · https://huggingface.co/api/organizations/{name}/resource-groups | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/settings/network-security openapi · GET · https://huggingface.co/api/organizations/{name}/settings/network-security | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| PATCH /api/organizations/{name}/settings/network-security openapi · PATCH · https://huggingface.co/api/organizations/{name}/settings/network-security | Unknown never called automatically | PATCH with no declared reversibility auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/service-accounts openapi · GET · https://huggingface.co/api/organizations/{name}/service-accounts | Identity and accounts never called automatically | its name contains “accounts” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/organizations/{name}/service-accounts openapi · POST · https://huggingface.co/api/organizations/{name}/service-accounts | Identity and accounts never called automatically | its name contains “accounts” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/service-accounts/{serviceAccountId} openapi · GET · https://huggingface.co/api/organizations/{name}/service-accounts/{serviceAccountId} | Identity and accounts never called automatically | its name contains “accounts” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/organizations/{name}/service-accounts/{serviceAccountId} openapi · DELETE · https://huggingface.co/api/organizations/{name}/service-accounts/{serviceAccountId} | Identity and accounts never called automatically | its name contains “accounts” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/organizations/{name}/service-accounts/{serviceAccountId}/tokens openapi · POST · https://huggingface.co/api/organizations/{name}/service-accounts/{serviceAccountId}/tokens | Identity and accounts never called automatically | its name contains “accounts” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| PATCH /api/organizations/{name}/service-accounts/{serviceAccountId}/tokens/{tokenId} openapi · PATCH · https://huggingface.co/api/organizations/{name}/service-accounts/{serviceAccountId}/tokens/{tokenId} | Identity and accounts never called automatically | its name contains “accounts” auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/organizations/{name}/service-accounts/{serviceAccountId}/tokens/{tokenId} openapi · DELETE · https://huggingface.co/api/organizations/{name}/service-accounts/{serviceAccountId}/tokens/{tokenId} | Identity and accounts never called automatically | its name contains “accounts” auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/organizations/{name}/service-accounts/{serviceAccountId}/tokens/{tokenId}/rotate openapi · POST · https://huggingface.co/api/organizations/{name}/service-accounts/{serviceAccountId}/tokens/{tokenId}/rotate | Identity and accounts never called automatically | its name contains “accounts” auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/avatar openapi · GET · https://huggingface.co/api/organizations/{name}/avatar | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/members openapi · GET · https://huggingface.co/api/organizations/{name}/members | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| PUT /api/organizations/{name}/members/{username}/role openapi · PUT · https://huggingface.co/api/organizations/{name}/members/{username}/role | Unknown never called automatically | PUT with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/scim/v2/ServiceProviderConfig openapi · GET · https://huggingface.co/api/organizations/{name}/scim/v2/ServiceProviderConfig | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/scim/v2/ResourceTypes openapi · GET · https://huggingface.co/api/organizations/{name}/scim/v2/ResourceTypes | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/scim/v2/Schemas openapi · GET · https://huggingface.co/api/organizations/{name}/scim/v2/Schemas | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/scim/v2/Schemas/{schemaId} openapi · GET · https://huggingface.co/api/organizations/{name}/scim/v2/Schemas/{schemaId} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/scim/v2/Users openapi · GET · https://huggingface.co/api/organizations/{name}/scim/v2/Users | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/organizations/{name}/scim/v2/Users openapi · POST · https://huggingface.co/api/organizations/{name}/scim/v2/Users | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/scim/v2/Users/{userId} openapi · GET · https://huggingface.co/api/organizations/{name}/scim/v2/Users/{userId} | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| PUT /api/organizations/{name}/scim/v2/Users/{userId} openapi · PUT · https://huggingface.co/api/organizations/{name}/scim/v2/Users/{userId} | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| PATCH /api/organizations/{name}/scim/v2/Users/{userId} openapi · PATCH · https://huggingface.co/api/organizations/{name}/scim/v2/Users/{userId} | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/organizations/{name}/scim/v2/Users/{userId} openapi · DELETE · https://huggingface.co/api/organizations/{name}/scim/v2/Users/{userId} | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/scim/v2/Groups openapi · GET · https://huggingface.co/api/organizations/{name}/scim/v2/Groups | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/organizations/{name}/scim/v2/Groups openapi · POST · https://huggingface.co/api/organizations/{name}/scim/v2/Groups | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/scim/v2/Groups/{groupId} openapi · GET · https://huggingface.co/api/organizations/{name}/scim/v2/Groups/{groupId} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| PUT /api/organizations/{name}/scim/v2/Groups/{groupId} openapi · PUT · https://huggingface.co/api/organizations/{name}/scim/v2/Groups/{groupId} | Unknown never called automatically | PUT with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| PATCH /api/organizations/{name}/scim/v2/Groups/{groupId} openapi · PATCH · https://huggingface.co/api/organizations/{name}/scim/v2/Groups/{groupId} | Unknown never called automatically | PATCH with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/organizations/{name}/scim/v2/Groups/{groupId} openapi · DELETE · https://huggingface.co/api/organizations/{name}/scim/v2/Groups/{groupId} | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/scim-provisioning/v2/Users openapi · GET · https://huggingface.co/api/organizations/{name}/scim-provisioning/v2/Users | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/organizations/{name}/scim-provisioning/v2/Users openapi · POST · https://huggingface.co/api/organizations/{name}/scim-provisioning/v2/Users | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/scim-provisioning/v2/Users/{userId} openapi · GET · https://huggingface.co/api/organizations/{name}/scim-provisioning/v2/Users/{userId} | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| PUT /api/organizations/{name}/scim-provisioning/v2/Users/{userId} openapi · PUT · https://huggingface.co/api/organizations/{name}/scim-provisioning/v2/Users/{userId} | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| PATCH /api/organizations/{name}/scim-provisioning/v2/Users/{userId} openapi · PATCH · https://huggingface.co/api/organizations/{name}/scim-provisioning/v2/Users/{userId} | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/organizations/{name}/scim-provisioning/v2/Users/{userId} openapi · DELETE · https://huggingface.co/api/organizations/{name}/scim-provisioning/v2/Users/{userId} | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/scim-provisioning/v2/Groups openapi · GET · https://huggingface.co/api/organizations/{name}/scim-provisioning/v2/Groups | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/organizations/{name}/scim-provisioning/v2/Groups openapi · POST · https://huggingface.co/api/organizations/{name}/scim-provisioning/v2/Groups | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/scim-provisioning/v2/Groups/{groupId} openapi · GET · https://huggingface.co/api/organizations/{name}/scim-provisioning/v2/Groups/{groupId} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| PUT /api/organizations/{name}/scim-provisioning/v2/Groups/{groupId} openapi · PUT · https://huggingface.co/api/organizations/{name}/scim-provisioning/v2/Groups/{groupId} | Unknown never called automatically | PUT with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| PATCH /api/organizations/{name}/scim-provisioning/v2/Groups/{groupId} openapi · PATCH · https://huggingface.co/api/organizations/{name}/scim-provisioning/v2/Groups/{groupId} | Unknown never called automatically | PATCH with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/organizations/{name}/scim-provisioning/v2/Groups/{groupId} openapi · DELETE · https://huggingface.co/api/organizations/{name}/scim-provisioning/v2/Groups/{groupId} | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /oauth/register openapi · POST · https://huggingface.co/oauth/register | Identity and accounts never called automatically | its name contains “oauth” auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /oauth/device openapi · POST · https://huggingface.co/oauth/device | Identity and accounts never called automatically | its name contains “oauth” auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /oauth/userinfo openapi · GET · https://huggingface.co/oauth/userinfo | Identity and accounts never called automatically | its name contains “oauth” auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /oauth/userinfo openapi · POST · https://huggingface.co/oauth/userinfo | Identity and accounts never called automatically | its name contains “oauth” auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/registry/token openapi · GET · https://huggingface.co/api/registry/token | Identity and accounts never called automatically | its name contains “token” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/blog/{slug}/comment openapi · POST · https://huggingface.co/api/blog/{slug}/comment | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/blog/{slug}/comment/{commentId}/reply openapi · POST · https://huggingface.co/api/blog/{slug}/comment/{commentId}/reply | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/blog/{slug}/comment/{commentId}/reaction openapi · POST · https://huggingface.co/api/blog/{slug}/comment/{commentId}/reaction | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/blog/{slug}/comment/{commentId}/hide openapi · POST · https://huggingface.co/api/blog/{slug}/comment/{commentId}/hide | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/blog/{slug}/comment/{commentId}/edit openapi · POST · https://huggingface.co/api/blog/{slug}/comment/{commentId}/edit | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/blog/{namespace}/{slug}/comment openapi · POST · https://huggingface.co/api/blog/{namespace}/{slug}/comment | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/blog/{namespace}/{slug}/comment/{commentId}/reply openapi · POST · https://huggingface.co/api/blog/{namespace}/{slug}/comment/{commentId}/reply | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/blog/{namespace}/{slug}/comment/{commentId}/reaction openapi · POST · https://huggingface.co/api/blog/{namespace}/{slug}/comment/{commentId}/reaction | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/blog/{namespace}/{slug}/comment/{commentId}/hide openapi · POST · https://huggingface.co/api/blog/{namespace}/{slug}/comment/{commentId}/hide | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/blog/{namespace}/{slug}/comment/{commentId}/edit openapi · POST · https://huggingface.co/api/blog/{namespace}/{slug}/comment/{commentId}/edit | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/blog/{namespace}/{slug}/resource-group openapi · GET · https://huggingface.co/api/blog/{namespace}/{slug}/resource-group | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/blog/{namespace}/{slug}/resource-group openapi · POST · https://huggingface.co/api/blog/{namespace}/{slug}/resource-group | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/blog/zh openapi · GET · https://huggingface.co/api/blog/zh | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/docs openapi · GET · https://huggingface.co/api/docs | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/docs/search openapi · GET · https://huggingface.co/api/docs/search | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/docs/search/full-text openapi · GET · https://huggingface.co/api/docs/search/full-text | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/whoami-v2 openapi · GET · https://huggingface.co/api/whoami-v2 | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/billing/usage-v2 openapi · GET · https://huggingface.co/api/organizations/{name}/billing/usage-v2 | Financial never called automatically | its name contains “billing” auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/billing/usage-by-resource-group openapi · GET · https://huggingface.co/api/organizations/{name}/billing/usage-by-resource-group | Financial never called automatically | its name contains “billing” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/billing/usage-by-inference-session openapi · GET · https://huggingface.co/api/organizations/{name}/billing/usage-by-inference-session | Financial never called automatically | its name contains “billing” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/billing/usage/inference openapi · GET · https://huggingface.co/api/organizations/{name}/billing/usage/inference | Financial never called automatically | its name contains “billing” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/billing/usage/live openapi · GET · https://huggingface.co/api/organizations/{name}/billing/usage/live | Financial never called automatically | its name contains “billing” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/settings/billing/usage-v2 openapi · GET · https://huggingface.co/api/settings/billing/usage-v2 | Financial never called automatically | its name contains “billing” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/settings/billing/usage-by-inference-session openapi · GET · https://huggingface.co/api/settings/billing/usage-by-inference-session | Financial never called automatically | its name contains “billing” auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/settings/billing/usage/jobs openapi · GET · https://huggingface.co/api/settings/billing/usage/jobs | Financial never called automatically | its name contains “billing” auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/settings/billing/usage/live openapi · GET · https://huggingface.co/api/settings/billing/usage/live | Financial never called automatically | its name contains “billing” auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/settings/metrics/live openapi · GET · https://huggingface.co/api/settings/metrics/live | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/users/{username}/billing/usage/live openapi · GET · https://huggingface.co/api/users/{username}/billing/usage/live | Financial never called automatically | its name contains “billing” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/users/{username}/overview openapi · GET · https://huggingface.co/api/users/{username}/overview | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/users/{username}/socials openapi · GET · https://huggingface.co/api/users/{username}/socials | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/users/{username}/avatar openapi · GET · https://huggingface.co/api/users/{username}/avatar | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/users/{username}/likes openapi · GET · https://huggingface.co/api/users/{username}/likes | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/users/{username}/followers openapi · GET · https://huggingface.co/api/users/{username}/followers | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/users/{username}/following openapi · GET · https://huggingface.co/api/users/{username}/following | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/users/{username}/following/orgs openapi · GET · https://huggingface.co/api/users/{username}/following/orgs | Identity and accounts never called automatically | its name contains “users” auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/organizations/{name}/socials openapi · GET · https://huggingface.co/api/organizations/{name}/socials | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/avatars/{namespace} openapi · GET · https://huggingface.co/api/avatars/{namespace} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/inference-endpoints/{namespace}/auth-check/{perms} openapi · POST · https://huggingface.co/api/inference-endpoints/{namespace}/auth-check/{perms} | Identity and accounts never called automatically | its name contains “auth” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/inference-endpoints/{namespace}/{endpoint}/auth-check/{perms} openapi · POST · https://huggingface.co/api/inference-endpoints/{namespace}/{endpoint}/auth-check/{perms} | Identity and accounts never called automatically | its name contains “auth” auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/jobs/{namespace}/auth-check/{perms} openapi · POST · https://huggingface.co/api/jobs/{namespace}/auth-check/{perms} | Identity and accounts never called automatically | its name contains “auth” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/jobs/{namespace}/{jobId}/auth-check/{perms} openapi · POST · https://huggingface.co/api/jobs/{namespace}/{jobId}/auth-check/{perms} | Identity and accounts never called automatically | its name contains “auth” auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/models/{namespace}/{repo}/likers openapi · GET · https://huggingface.co/api/models/{namespace}/{repo}/likers | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/datasets/{namespace}/{repo}/likers openapi · GET · https://huggingface.co/api/datasets/{namespace}/{repo}/likers | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/{namespace}/{repo}/likers openapi · GET · https://huggingface.co/api/spaces/{namespace}/{repo}/likers | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/kernels/{namespace}/{repo}/likers openapi · GET · https://huggingface.co/api/kernels/{namespace}/{repo}/likers | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/models/{namespace}/{repo}/treesize/{rev}/{path} openapi · GET · https://huggingface.co/api/models/{namespace}/{repo}/treesize/{rev}/{path} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/{namespace}/{repo}/treesize/{rev}/{path} openapi · GET · https://huggingface.co/api/spaces/{namespace}/{repo}/treesize/{rev}/{path} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/datasets/{namespace}/{repo}/treesize/{rev}/{path} openapi · GET · https://huggingface.co/api/datasets/{namespace}/{repo}/treesize/{rev}/{path} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/models/{namespace}/{repo}/lfs-files openapi · GET · https://huggingface.co/api/models/{namespace}/{repo}/lfs-files | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/datasets/{namespace}/{repo}/lfs-files openapi · GET · https://huggingface.co/api/datasets/{namespace}/{repo}/lfs-files | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/{namespace}/{repo}/lfs-files openapi · GET · https://huggingface.co/api/spaces/{namespace}/{repo}/lfs-files | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/models/{namespace}/{repo}/lfs-files/batch openapi · POST · https://huggingface.co/api/models/{namespace}/{repo}/lfs-files/batch | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/datasets/{namespace}/{repo}/lfs-files/batch openapi · POST · https://huggingface.co/api/datasets/{namespace}/{repo}/lfs-files/batch | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/spaces/{namespace}/{repo}/lfs-files/batch openapi · POST · https://huggingface.co/api/spaces/{namespace}/{repo}/lfs-files/batch | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/models/{namespace}/{repo}/lfs-files/{sha} openapi · DELETE · https://huggingface.co/api/models/{namespace}/{repo}/lfs-files/{sha} | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/datasets/{namespace}/{repo}/lfs-files/{sha} openapi · DELETE · https://huggingface.co/api/datasets/{namespace}/{repo}/lfs-files/{sha} | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/spaces/{namespace}/{repo}/lfs-files/{sha} openapi · DELETE · https://huggingface.co/api/spaces/{namespace}/{repo}/lfs-files/{sha} | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/models/{namespace}/{repo}/lfs-files/duplicate openapi · POST · https://huggingface.co/api/models/{namespace}/{repo}/lfs-files/duplicate | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/kernels/{namespace}/{repo}/lfs-files/duplicate openapi · POST · https://huggingface.co/api/kernels/{namespace}/{repo}/lfs-files/duplicate | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/datasets/{namespace}/{repo}/lfs-files/duplicate openapi · POST · https://huggingface.co/api/datasets/{namespace}/{repo}/lfs-files/duplicate | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/spaces/{namespace}/{repo}/lfs-files/duplicate openapi · POST · https://huggingface.co/api/spaces/{namespace}/{repo}/lfs-files/duplicate | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/buckets/{namespace}/{repo}/lfs-files/duplicate openapi · POST · https://huggingface.co/api/buckets/{namespace}/{repo}/lfs-files/duplicate | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/models/{namespace}/{repo}/commits/{rev} openapi · GET · https://huggingface.co/api/models/{namespace}/{repo}/commits/{rev} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/{namespace}/{repo}/commits/{rev} openapi · GET · https://huggingface.co/api/spaces/{namespace}/{repo}/commits/{rev} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/datasets/{namespace}/{repo}/commits/{rev} openapi · GET · https://huggingface.co/api/datasets/{namespace}/{repo}/commits/{rev} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/models/{namespace}/{repo}/refs openapi · GET · https://huggingface.co/api/models/{namespace}/{repo}/refs | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/datasets/{namespace}/{repo}/refs openapi · GET · https://huggingface.co/api/datasets/{namespace}/{repo}/refs | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/{namespace}/{repo}/refs openapi · GET · https://huggingface.co/api/spaces/{namespace}/{repo}/refs | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/models/{namespace}/{repo}/compare/{compare} openapi · GET · https://huggingface.co/api/models/{namespace}/{repo}/compare/{compare} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/datasets/{namespace}/{repo}/compare/{compare} openapi · GET · https://huggingface.co/api/datasets/{namespace}/{repo}/compare/{compare} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/{namespace}/{repo}/compare/{compare} openapi · GET · https://huggingface.co/api/spaces/{namespace}/{repo}/compare/{compare} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/models/{namespace}/{repo}/paths-info/{rev} openapi · POST · https://huggingface.co/api/models/{namespace}/{repo}/paths-info/{rev} | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/datasets/{namespace}/{repo}/paths-info/{rev} openapi · POST · https://huggingface.co/api/datasets/{namespace}/{repo}/paths-info/{rev} | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/spaces/{namespace}/{repo}/paths-info/{rev} openapi · POST · https://huggingface.co/api/spaces/{namespace}/{repo}/paths-info/{rev} | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/models/{namespace}/{repo}/preupload/{rev} openapi · POST · https://huggingface.co/api/models/{namespace}/{repo}/preupload/{rev} | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/spaces/{namespace}/{repo}/preupload/{rev} openapi · POST · https://huggingface.co/api/spaces/{namespace}/{repo}/preupload/{rev} | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/datasets/{namespace}/{repo}/preupload/{rev} openapi · POST · https://huggingface.co/api/datasets/{namespace}/{repo}/preupload/{rev} | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/models/{namespace}/{repo}/xet-write-token/{rev} openapi · GET · https://huggingface.co/api/models/{namespace}/{repo}/xet-write-token/{rev} | Identity and accounts never called automatically | its name contains “token” auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/{namespace}/{repo}/xet-write-token/{rev} openapi · GET · https://huggingface.co/api/spaces/{namespace}/{repo}/xet-write-token/{rev} | Identity and accounts never called automatically | its name contains “token” auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/datasets/{namespace}/{repo}/xet-write-token/{rev} openapi · GET · https://huggingface.co/api/datasets/{namespace}/{repo}/xet-write-token/{rev} | Identity and accounts never called automatically | its name contains “token” auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/buckets/{namespace}/{repo}/xet-write-token openapi · GET · https://huggingface.co/api/buckets/{namespace}/{repo}/xet-write-token | Identity and accounts never called automatically | its name contains “token” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/containers/{namespace}/{repo}/xet-write-token openapi · GET · https://huggingface.co/api/containers/{namespace}/{repo}/xet-write-token | Identity and accounts never called automatically | its name contains “token” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/models/{namespace}/{repo}/xet-read-token/{rev} openapi · GET · https://huggingface.co/api/models/{namespace}/{repo}/xet-read-token/{rev} | Identity and accounts never called automatically | its name contains “token” auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/{namespace}/{repo}/xet-read-token/{rev} openapi · GET · https://huggingface.co/api/spaces/{namespace}/{repo}/xet-read-token/{rev} | Identity and accounts never called automatically | its name contains “token” auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/datasets/{namespace}/{repo}/xet-read-token/{rev} openapi · GET · https://huggingface.co/api/datasets/{namespace}/{repo}/xet-read-token/{rev} | Identity and accounts never called automatically | its name contains “token” auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/buckets/{namespace}/{repo}/xet-read-token openapi · GET · https://huggingface.co/api/buckets/{namespace}/{repo}/xet-read-token | Identity and accounts never called automatically | its name contains “token” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/containers/{namespace}/{repo}/xet-read-token openapi · GET · https://huggingface.co/api/containers/{namespace}/{repo}/xet-read-token | Identity and accounts never called automatically | its name contains “token” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/models/{namespace}/{repo}/commit/{rev} openapi · POST · https://huggingface.co/api/models/{namespace}/{repo}/commit/{rev} | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/datasets/{namespace}/{repo}/commit/{rev} openapi · POST · https://huggingface.co/api/datasets/{namespace}/{repo}/commit/{rev} | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/spaces/{namespace}/{repo}/commit/{rev} openapi · POST · https://huggingface.co/api/spaces/{namespace}/{repo}/commit/{rev} | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/models/{namespace}/{repo}/tag/{rev} openapi · POST · https://huggingface.co/api/models/{namespace}/{repo}/tag/{rev} | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/models/{namespace}/{repo}/tag/{rev} openapi · DELETE · https://huggingface.co/api/models/{namespace}/{repo}/tag/{rev} | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/spaces/{namespace}/{repo}/tag/{rev} openapi · POST · https://huggingface.co/api/spaces/{namespace}/{repo}/tag/{rev} | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/spaces/{namespace}/{repo}/tag/{rev} openapi · DELETE · https://huggingface.co/api/spaces/{namespace}/{repo}/tag/{rev} | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/datasets/{namespace}/{repo}/tag/{rev} openapi · POST · https://huggingface.co/api/datasets/{namespace}/{repo}/tag/{rev} | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/datasets/{namespace}/{repo}/tag/{rev} openapi · DELETE · https://huggingface.co/api/datasets/{namespace}/{repo}/tag/{rev} | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/models/{namespace}/{repo}/branch/{rev} openapi · POST · https://huggingface.co/api/models/{namespace}/{repo}/branch/{rev} | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/models/{namespace}/{repo}/branch/{rev} openapi · DELETE · https://huggingface.co/api/models/{namespace}/{repo}/branch/{rev} | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/spaces/{namespace}/{repo}/branch/{rev} openapi · POST · https://huggingface.co/api/spaces/{namespace}/{repo}/branch/{rev} | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/spaces/{namespace}/{repo}/branch/{rev} openapi · DELETE · https://huggingface.co/api/spaces/{namespace}/{repo}/branch/{rev} | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/datasets/{namespace}/{repo}/branch/{rev} openapi · POST · https://huggingface.co/api/datasets/{namespace}/{repo}/branch/{rev} | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/datasets/{namespace}/{repo}/branch/{rev} openapi · DELETE · https://huggingface.co/api/datasets/{namespace}/{repo}/branch/{rev} | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/models/{namespace}/{repo}/resource-group openapi · GET · https://huggingface.co/api/models/{namespace}/{repo}/resource-group | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/models/{namespace}/{repo}/resource-group openapi · POST · https://huggingface.co/api/models/{namespace}/{repo}/resource-group | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/{namespace}/{repo}/resource-group openapi · GET · https://huggingface.co/api/spaces/{namespace}/{repo}/resource-group | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/spaces/{namespace}/{repo}/resource-group openapi · POST · https://huggingface.co/api/spaces/{namespace}/{repo}/resource-group | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/datasets/{namespace}/{repo}/resource-group openapi · GET · https://huggingface.co/api/datasets/{namespace}/{repo}/resource-group | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/datasets/{namespace}/{repo}/resource-group openapi · POST · https://huggingface.co/api/datasets/{namespace}/{repo}/resource-group | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/buckets/{namespace}/{repo}/resource-group openapi · GET · https://huggingface.co/api/buckets/{namespace}/{repo}/resource-group | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/buckets/{namespace}/{repo}/resource-group openapi · POST · https://huggingface.co/api/buckets/{namespace}/{repo}/resource-group | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/models/{namespace}/{repo}/super-squash/{rev} openapi · POST · https://huggingface.co/api/models/{namespace}/{repo}/super-squash/{rev} | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/datasets/{namespace}/{repo}/super-squash/{rev} openapi · POST · https://huggingface.co/api/datasets/{namespace}/{repo}/super-squash/{rev} | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/spaces/{namespace}/{repo}/super-squash/{rev} openapi · POST · https://huggingface.co/api/spaces/{namespace}/{repo}/super-squash/{rev} | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| PUT /api/models/{namespace}/{repo}/settings openapi · PUT · https://huggingface.co/api/models/{namespace}/{repo}/settings | Unknown never called automatically | PUT with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| PUT /api/spaces/{namespace}/{repo}/settings openapi · PUT · https://huggingface.co/api/spaces/{namespace}/{repo}/settings | Unknown never called automatically | PUT with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| PUT /api/datasets/{namespace}/{repo}/settings openapi · PUT · https://huggingface.co/api/datasets/{namespace}/{repo}/settings | Unknown never called automatically | PUT with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/models/{namespace}/{repo}/tree/{rev}/{path} openapi · GET · https://huggingface.co/api/models/{namespace}/{repo}/tree/{rev}/{path} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/{namespace}/{repo}/tree/{rev}/{path} openapi · GET · https://huggingface.co/api/spaces/{namespace}/{repo}/tree/{rev}/{path} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/datasets/{namespace}/{repo}/tree/{rev}/{path} openapi · GET · https://huggingface.co/api/datasets/{namespace}/{repo}/tree/{rev}/{path} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/models/{namespace}/{repo}/notebook/{rev}/{path} openapi · GET · https://huggingface.co/api/models/{namespace}/{repo}/notebook/{rev}/{path} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/datasets/{namespace}/{repo}/notebook/{rev}/{path} openapi · GET · https://huggingface.co/api/datasets/{namespace}/{repo}/notebook/{rev}/{path} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/{namespace}/{repo}/notebook/{rev}/{path} openapi · GET · https://huggingface.co/api/spaces/{namespace}/{repo}/notebook/{rev}/{path} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/models/{namespace}/{repo}/scan openapi · GET · https://huggingface.co/api/models/{namespace}/{repo}/scan | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/datasets/{namespace}/{repo}/scan openapi · GET · https://huggingface.co/api/datasets/{namespace}/{repo}/scan | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/{namespace}/{repo}/scan openapi · GET · https://huggingface.co/api/spaces/{namespace}/{repo}/scan | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/kernels/{namespace}/{repo}/scan openapi · GET · https://huggingface.co/api/kernels/{namespace}/{repo}/scan | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/{repoType}/{namespace}/{repo}/discussions openapi · GET · https://huggingface.co/api/{repoType}/{namespace}/{repo}/discussions | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/{repoType}/{namespace}/{repo}/discussions openapi · POST · https://huggingface.co/api/{repoType}/{namespace}/{repo}/discussions | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/{repoType}/{namespace}/{repo}/discussions/{num} openapi · GET · https://huggingface.co/api/{repoType}/{namespace}/{repo}/discussions/{num} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/{repoType}/{namespace}/{repo}/discussions/{num} openapi · DELETE · https://huggingface.co/api/{repoType}/{namespace}/{repo}/discussions/{num} | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/{repoType}/{namespace}/{repo}/discussions/{num}/comment openapi · POST · https://huggingface.co/api/{repoType}/{namespace}/{repo}/discussions/{num}/comment | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/{repoType}/{namespace}/{repo}/discussions/{num}/status openapi · POST · https://huggingface.co/api/{repoType}/{namespace}/{repo}/discussions/{num}/status | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/{repoType}/{namespace}/{repo}/discussions/{num}/title openapi · POST · https://huggingface.co/api/{repoType}/{namespace}/{repo}/discussions/{num}/title | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/{repoType}/{namespace}/{repo}/discussions/{num}/pin openapi · POST · https://huggingface.co/api/{repoType}/{namespace}/{repo}/discussions/{num}/pin | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/{repoType}/{namespace}/{repo}/discussions/{num}/merge openapi · POST · https://huggingface.co/api/{repoType}/{namespace}/{repo}/discussions/{num}/merge | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/{repoType}/{namespace}/{repo}/discussions/{num}/ref openapi · DELETE · https://huggingface.co/api/{repoType}/{namespace}/{repo}/discussions/{num}/ref | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/{repoType}/{namespace}/{repo}/discussions/{num}/storage openapi · GET · https://huggingface.co/api/{repoType}/{namespace}/{repo}/discussions/{num}/storage | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/{repoType}/{namespace}/{repo}/discussions/{num}/ignore openapi · POST · https://huggingface.co/api/{repoType}/{namespace}/{repo}/discussions/{num}/ignore | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/{repoType}/{namespace}/{repo}/discussions/{num}/comment/{commentId}/edit openapi · POST · https://huggingface.co/api/{repoType}/{namespace}/{repo}/discussions/{num}/comment/{commentId}/edit | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 5 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/{repoType}/{namespace}/{repo}/discussions/{num}/comment/{commentId}/hide openapi · POST · https://huggingface.co/api/{repoType}/{namespace}/{repo}/discussions/{num}/comment/{commentId}/hide | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 5 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/{repoType}/{namespace}/{repo}/discussions/{num}/comment/{commentId}/reaction openapi · POST · https://huggingface.co/api/{repoType}/{namespace}/{repo}/discussions/{num}/comment/{commentId}/reaction | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 5 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/kernels openapi · GET · https://huggingface.co/api/kernels | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/kernels/{namespace}/{repo} openapi · GET · https://huggingface.co/api/kernels/{namespace}/{repo} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/kernels/{namespace}/{repo}/revision/{rev} openapi · GET · https://huggingface.co/api/kernels/{namespace}/{repo}/revision/{rev} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/kernels/access-request/approve openapi · POST · https://huggingface.co/api/kernels/access-request/approve | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/datasets/{namespace}/{repo}/leaderboard openapi · GET · https://huggingface.co/api/datasets/{namespace}/{repo}/leaderboard | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/models/{namespace}/{repo}/jwt openapi · GET · https://huggingface.co/api/models/{namespace}/{repo}/jwt | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/{namespace}/{repo}/jwt openapi · GET · https://huggingface.co/api/spaces/{namespace}/{repo}/jwt | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/datasets/{namespace}/{repo}/jwt openapi · GET · https://huggingface.co/api/datasets/{namespace}/{repo}/jwt | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/agent-harnesses openapi · GET · https://huggingface.co/api/agent-harnesses | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/models-tags-by-type openapi · GET · https://huggingface.co/api/models-tags-by-type | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/datasets-tags-by-type openapi · GET · https://huggingface.co/api/datasets-tags-by-type | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/trending openapi · GET · https://huggingface.co/api/trending | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/quicksearch openapi · GET · https://huggingface.co/api/quicksearch | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/quicksearch openapi · POST · https://huggingface.co/api/quicksearch | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/search/full-text openapi · GET · https://huggingface.co/api/search/full-text | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/hardware openapi · GET · https://huggingface.co/api/spaces/hardware | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/templates openapi · GET · https://huggingface.co/api/spaces/templates | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/zero-gpu/quota openapi · GET · https://huggingface.co/api/spaces/zero-gpu/quota | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/{namespace}/{repo}/secrets openapi · GET · https://huggingface.co/api/spaces/{namespace}/{repo}/secrets | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/spaces/{namespace}/{repo}/secrets openapi · POST · https://huggingface.co/api/spaces/{namespace}/{repo}/secrets | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/spaces/{namespace}/{repo}/secrets openapi · DELETE · https://huggingface.co/api/spaces/{namespace}/{repo}/secrets | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/{namespace}/{repo}/variables openapi · GET · https://huggingface.co/api/spaces/{namespace}/{repo}/variables | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/spaces/{namespace}/{repo}/variables openapi · POST · https://huggingface.co/api/spaces/{namespace}/{repo}/variables | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/spaces/{namespace}/{repo}/variables openapi · DELETE · https://huggingface.co/api/spaces/{namespace}/{repo}/variables | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/{repoType}/{namespace}/{repo}/duplicate openapi · POST · https://huggingface.co/api/{repoType}/{namespace}/{repo}/duplicate | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/{repoType}/{namespace}/{repo}/duplicate/status openapi · GET · https://huggingface.co/api/{repoType}/{namespace}/{repo}/duplicate/status | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/repos/create openapi · POST · https://huggingface.co/api/repos/create | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/repos/move openapi · POST · https://huggingface.co/api/repos/move | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| PATCH /api/{repoType}/{namespace}/{repo}/sql-console/embed/{id} openapi · PATCH · https://huggingface.co/api/{repoType}/{namespace}/{repo}/sql-console/embed/{id} | Unknown never called automatically | PATCH with no declared reversibility auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/{repoType}/{namespace}/{repo}/sql-console/embed/{id} openapi · DELETE · https://huggingface.co/api/{repoType}/{namespace}/{repo}/sql-console/embed/{id} | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/{repoType}/{namespace}/{repo}/sql-console/embed/{id}/hide openapi · POST · https://huggingface.co/api/{repoType}/{namespace}/{repo}/sql-console/embed/{id}/hide | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/{repoType}/{namespace}/{repo}/sql-console/embed openapi · POST · https://huggingface.co/api/{repoType}/{namespace}/{repo}/sql-console/embed | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /spaces/{namespace}/{repo}/resolve/{rev}/{path} openapi · GET · https://huggingface.co/spaces/{namespace}/{repo}/resolve/{rev}/{path} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /datasets/{namespace}/{repo}/resolve/{rev}/{path} openapi · GET · https://huggingface.co/datasets/{namespace}/{repo}/resolve/{rev}/{path} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /{namespace}/{repo}/resolve/{rev}/{path} openapi · GET · https://huggingface.co/{namespace}/{repo}/resolve/{rev}/{path} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/resolve-cache/spaces/{namespace}/{repo}/{rev}/{path} openapi · GET · https://huggingface.co/api/resolve-cache/spaces/{namespace}/{repo}/{rev}/{path} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/resolve-cache/datasets/{namespace}/{repo}/{rev}/{path} openapi · GET · https://huggingface.co/api/resolve-cache/datasets/{namespace}/{repo}/{rev}/{path} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/resolve-cache/models/{namespace}/{repo}/{rev}/{path} openapi · GET · https://huggingface.co/api/resolve-cache/models/{namespace}/{repo}/{rev}/{path} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 4 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /{namespace}/{repo}/ask-access openapi · POST · https://huggingface.co/{namespace}/{repo}/ask-access | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /datasets/{namespace}/{repo}/ask-access openapi · POST · https://huggingface.co/datasets/{namespace}/{repo}/ask-access | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /{namespace}/{repo}/user-access-report openapi · GET · https://huggingface.co/{namespace}/{repo}/user-access-report | Identity and accounts never called automatically | its name contains “user” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /datasets/{namespace}/{repo}/user-access-report openapi · GET · https://huggingface.co/datasets/{namespace}/{repo}/user-access-report | Identity and accounts never called automatically | its name contains “user” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/models/{namespace}/{repo}/user-access-request/cancel openapi · POST · https://huggingface.co/api/models/{namespace}/{repo}/user-access-request/cancel | Identity and accounts never called automatically | its name contains “user” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/datasets/{namespace}/{repo}/user-access-request/cancel openapi · POST · https://huggingface.co/api/datasets/{namespace}/{repo}/user-access-request/cancel | Identity and accounts never called automatically | its name contains “user” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/models/{namespace}/{repo}/user-access-request/{status} openapi · GET · https://huggingface.co/api/models/{namespace}/{repo}/user-access-request/{status} | Identity and accounts never called automatically | its name contains “user” auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/datasets/{namespace}/{repo}/user-access-request/{status} openapi · GET · https://huggingface.co/api/datasets/{namespace}/{repo}/user-access-request/{status} | Identity and accounts never called automatically | its name contains “user” auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/models/{namespace}/{repo}/user-access-request/handle openapi · POST · https://huggingface.co/api/models/{namespace}/{repo}/user-access-request/handle | Identity and accounts never called automatically | its name contains “user” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/datasets/{namespace}/{repo}/user-access-request/handle openapi · POST · https://huggingface.co/api/datasets/{namespace}/{repo}/user-access-request/handle | Identity and accounts never called automatically | its name contains “user” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/models/{namespace}/{repo}/user-access-request/batch openapi · POST · https://huggingface.co/api/models/{namespace}/{repo}/user-access-request/batch | Identity and accounts never called automatically | its name contains “user” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/datasets/{namespace}/{repo}/user-access-request/batch openapi · POST · https://huggingface.co/api/datasets/{namespace}/{repo}/user-access-request/batch | Identity and accounts never called automatically | its name contains “user” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/models/{namespace}/{repo}/user-access-request/grant openapi · POST · https://huggingface.co/api/models/{namespace}/{repo}/user-access-request/grant | Identity and accounts never called automatically | its name contains “user” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/datasets/{namespace}/{repo}/user-access-request/grant openapi · POST · https://huggingface.co/api/datasets/{namespace}/{repo}/user-access-request/grant | Identity and accounts never called automatically | its name contains “user” auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| PUT /api/spaces/{namespace}/{repo}/volumes openapi · PUT · https://huggingface.co/api/spaces/{namespace}/{repo}/volumes | Unknown never called automatically | PUT with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/spaces/{namespace}/{repo}/volumes openapi · DELETE · https://huggingface.co/api/spaces/{namespace}/{repo}/volumes | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/spaces/{namespace}/{repo}/hardware openapi · POST · https://huggingface.co/api/spaces/{namespace}/{repo}/hardware | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/spaces/{namespace}/{repo}/sleeptime openapi · POST · https://huggingface.co/api/spaces/{namespace}/{repo}/sleeptime | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/{namespace}/{repo}/logs/{logType} openapi · GET · https://huggingface.co/api/spaces/{namespace}/{repo}/logs/{logType} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/{namespace}/{repo}/events openapi · GET · https://huggingface.co/api/spaces/{namespace}/{repo}/events | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/{namespace}/{repo}/metrics openapi · GET · https://huggingface.co/api/spaces/{namespace}/{repo}/metrics | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/spaces/{namespace}/{repo}/dev-mode openapi · POST · https://huggingface.co/api/spaces/{namespace}/{repo}/dev-mode | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/spaces/{namespace}/{repo}/custom-domain openapi · POST · https://huggingface.co/api/spaces/{namespace}/{repo}/custom-domain | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/semantic-search openapi · GET · https://huggingface.co/api/spaces/semantic-search | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/spaces/featured openapi · GET · https://huggingface.co/api/spaces/featured | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/daily_papers openapi · GET · https://huggingface.co/api/daily_papers | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/papers openapi · GET · https://huggingface.co/api/papers | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/papers/search openapi · GET · https://huggingface.co/api/papers/search | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/papers/index openapi · POST · https://huggingface.co/api/papers/index | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 0 | not attempted requires http_bearer: never called without the operator's own credentials |
| GET /api/papers/{paperId} openapi · GET · https://huggingface.co/api/papers/{paperId} | Authenticated read-only never called automatically | HTTP GET behind http_bearer auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/papers/{paperId}/comment openapi · POST · https://huggingface.co/api/papers/{paperId}/comment | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/papers/{paperId}/comment/{commentId}/reply openapi · POST · https://huggingface.co/api/papers/{paperId}/comment/{commentId}/reply | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/papers/{paperId}/comment/{commentId}/edit openapi · POST · https://huggingface.co/api/papers/{paperId}/comment/{commentId}/edit | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/papers/{paperId}/comment/{commentId}/hide openapi · POST · https://huggingface.co/api/papers/{paperId}/comment/{commentId}/hide | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/papers/{paperId}/comment/{commentId}/reaction openapi · POST · https://huggingface.co/api/papers/{paperId}/comment/{commentId}/reaction | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/papers/{paperId}/links openapi · POST · https://huggingface.co/api/papers/{paperId}/links | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 1 | not attempted requires http_bearer: never called without the operator's own credentials |
| DELETE /api/posts/{username}/{postSlug} openapi · DELETE · https://huggingface.co/api/posts/{username}/{postSlug} | Irreversible write never called automatically | HTTP DELETE auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/posts/{username}/{postSlug}/comment openapi · POST · https://huggingface.co/api/posts/{username}/{postSlug}/comment | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 2 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/posts/{username}/{postSlug}/comment/{commentId}/reply openapi · POST · https://huggingface.co/api/posts/{username}/{postSlug}/comment/{commentId}/reply | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
| POST /api/posts/{username}/{postSlug}/comment/{commentId}/reaction openapi · POST · https://huggingface.co/api/posts/{username}/{postSlug}/comment/{commentId}/reaction | Unknown never called automatically | POST with no declared reversibility auth: http_bearer · required inputs: 3 | not attempted requires http_bearer: never called without the operator's own credentials |
Where the declaration and the call disagree
None: every capability that was called answered as declared.
Signed certificate
This page’s rows, signed by the observer’s Ed25519 key: every capability’s id, endpoint, safety class, policy class and observed state, the declaration hashes and the record’s sealed manifest. The certificate is derived from the record alone, so the same record always yields the same id.
alg Ed25519 · kid hcIAczGf-8EFBnkunmZlvFWnD2nHHeHeC9cM4BTiBVo
sig rrrKtH23sV7Piwq2CliAsDAZbLD1uWhUb-r5_0YjeAemYSsAqbmkCS_1Cs8_iB0luRLkVq6HwnWsxoGFQz7pBg
The certificate as JSON · verify it now · the key directory · machine-readability certificate
To verify it yourself: SHA-256 the certificate object as canonical JSON (keys sorted, no whitespace); the hex digest must equal certificate_sha256 and the id; then check the Ed25519 signature over "crawlcheck-capability-certificate-v1\n" followed by that hex digest, with the key in the directory whose RFC 7638 thumbprint is the kid.
Policy classes
| Policy class | Called automatically? | Rule |
|---|---|---|
| Public read-only public_read_only | yes, to verify | May be called without credentials. CrawlCheck calls it only to check the declaration: GET with no input, on the scanned origin. |
| Authenticated read-only authenticated_read_only | never | Never called by CrawlCheck. An agent needs the user's own credentials and consent. |
| Reversible write reversible_write | never | Never invoked automatically. Needs the owner's written authorisation and a test account. |
| Irreversible write irreversible_write | never | Never invoked automatically. Deletes or changes something that cannot be undone. |
| Financial financial | never | Never invoked automatically. Moves money or creates a charge. |
| External communication external_communication | never | Never invoked automatically. Sends a message, email or notification to someone. |
| Identity and accounts identity | never | Never invoked automatically. Creates, signs in to or changes an account or credential. |
| Unknown unknown | never | Never invoked. Its effect cannot be read from the declaration, so it is treated as the riskiest case. |
| Metadata metadata | never | Nothing to invoke: a listing, a server card or a skill file, not an operation. |