jsdrop.
REST API

A server with an API.

The editor and automation share the same public guest project model. All endpoints return JSON.

Create a project

Templates: hello (the default), blank, express, hono, fastify, koa, websocket, mcp, scraper, markdown, shortener, and worker.

curl -X POST https://jsdrop.com/api/v1/projects \
  -H "Content-Type: application/json" \
  -d '{"template":"express","title":"My API"}'

Read and edit

GET a project to retrieve its state and revision. PATCH accepts metadata and/or a complete state. Source updates require the current revision to prevent overwriting concurrent edits. Guest hashes cannot be renamed, deleted, claimed, or made private through the API.

GET   /api/v1/projects/{slug}
PATCH /api/v1/projects/{slug}

{
  "revision": "revision-from-GET",
  "state": {
    "code": "console.log(42)",
    "package": "{ \"type\": \"module\", \"dependencies\": {} }"
  }
}

Versions, restores, and forks

POST /api/v1/projects/{slug}/versions
GET  /api/v1/projects/{slug}/versions
GET  /api/v1/projects/{slug}/versions/1
POST /api/v1/projects/{slug}/restore  {"version":1}
POST /api/v1/projects/{slug}/fork     {"version":1}
GET  /api/v1/projects/{slug}/export
GET  /api/v1/projects/{slug}/events   (server-sent events for new versions)

Deploys and variables (Pro)

These need a signed-in session as the drop’s owner, with Pro. PUT env replaces all variables; send null as a value to keep a variable’s current value.

POST /api/v1/projects/{slug}/deploy  {"enabled":true}
GET  /api/v1/projects/{slug}/logs
PUT  /api/v1/projects/{slug}/env     {"env":{"API_KEY":"…","OLD_KEY":null}}

Limits and errors

index.ts may contain up to 512 KB and package.json up to 64 KB of UTF-8 text. Mutations are rate limited; project creation is limited to 20 requests per IP per minute. Error responses use a message field. 402 means a feature needs Pro, 409 indicates a stale revision or duplicate version, and 429 indicates a rate limit.

API origin policy

Browser mutations are limited to the configured application origin. CLI and MCP requests without an Origin header are accepted. There are no authentication tokens for guest projects: editor URLs deliberately grant collaborative access.

Made to be explored. Open the workspace and try it for yourself. Coming from Val Town, Replit, or Glitch? See how jsdrop compares.