{"schemaVersion":"hugging-bay.publisher-workflow.v1","generatedAt":"2026-09-08T18:16:55.891Z","baseUrl":"https://huggingbay.xyz","access":{"launchKitUrl":"https://huggingbay.xyz/publishers/launch-kit","launchKitApi":"https://huggingbay.xyz/api/publishers/launch-kit","releaseTemplateUrl":"https://huggingbay.xyz/publishers/release-template","releaseTemplateApi":"https://huggingbay.xyz/api/publishers/release-template","applyUrl":"https://huggingbay.xyz/publishers/apply","applicationApi":"https://huggingbay.xyz/api/publisher-applications","applicationStatusApi":"https://huggingbay.xyz/api/publisher-applications/{caseId}","requiredRole":"publisher or admin","tokenValidation":"https://huggingbay.xyz/api/me","apiKeysApi":"https://huggingbay.xyz/api/publisher/api-keys","allowedOwnersSource":"Configured publisher bearer tokens, HUGGING_BAY_PUBLISHER_OWNERS, and reviewed scoped publisher API keys.","policy":"Publisher applications create a review case and status URL. Tokens are issued only after Hugging Bay review; approved publishers can create and revoke additional scoped automation tokens."},"apiFlow":[{"step":"read-launch-kit","method":"GET","url":"https://huggingbay.xyz/api/publishers/launch-kit","auth":"none"},{"step":"copy-release-template","method":"GET","url":"https://huggingbay.xyz/api/publishers/release-template?kind=llm","auth":"none"},{"step":"apply","method":"POST","url":"https://huggingbay.xyz/api/publisher-applications","auth":"none"},{"step":"check-application","method":"GET","url":"https://huggingbay.xyz/api/publisher-applications/{caseId}","auth":"none"},{"step":"validate-token","method":"GET","url":"https://huggingbay.xyz/api/me","auth":"bearer"},{"step":"list-api-keys","method":"GET","url":"https://huggingbay.xyz/api/publisher/api-keys","auth":"publisher"},{"step":"create-api-key","method":"POST","url":"https://huggingbay.xyz/api/publisher/api-keys","auth":"publisher"},{"step":"revoke-api-key","method":"DELETE","url":"https://huggingbay.xyz/api/publisher/api-keys/{keyId}","auth":"publisher"},{"step":"small-release","method":"POST","url":"https://huggingbay.xyz/api/artifacts","auth":"publisher"},{"step":"large-upload-session","method":"POST","url":"https://huggingbay.xyz/api/upload-sessions","auth":"publisher"},{"step":"inspect-upload-session","method":"GET","url":"https://huggingbay.xyz/api/upload-sessions/{sessionId}?refresh=1","auth":"publisher"},{"step":"resume-upload-session","method":"POST","url":"https://huggingbay.xyz/api/upload-sessions/{sessionId}/resume","auth":"publisher"},{"step":"complete-upload-session","method":"POST","url":"https://huggingbay.xyz/api/upload-sessions/{sessionId}/complete","auth":"publisher"},{"step":"run-release-checks","method":"POST","url":"https://huggingbay.xyz/api/artifacts/{artifactId}/run-checks","auth":"publisher"},{"step":"publish-release","method":"POST","url":"https://huggingbay.xyz/api/artifacts/{artifactId}/publish","auth":"publisher"},{"step":"read-trust-bundle","method":"GET","url":"https://huggingbay.xyz/api/trust-bundles/{artifactId}","auth":"none for public artifacts"},{"step":"submit-reviewed-fallback","method":"POST","url":"https://huggingbay.xyz/api/artifacts/{artifactId}/decentralized-fallbacks","auth":"none to queue reviewed metadata"}],"cliFlow":["curl -s https://huggingbay.xyz/api/publishers/launch-kit","curl -s https://huggingbay.xyz/api/publishers/release-template?kind=llm > hugging-bay-release-template.json","bay publisher-workflow --api https://huggingbay.xyz","bay publisher-apply application.json --api https://huggingbay.xyz","bay whoami --token <publisher-token> --api https://huggingbay.xyz","bay publisher-keys --token <publisher-token> --api https://huggingbay.xyz","bay publisher-key-create --owner <namespace> --display-name ci-bot --token <publisher-token> --api https://huggingbay.xyz","bay publish draft.json --files-dir ./release-files --token <publisher-token> --api https://huggingbay.xyz","bay upload-session draft.json --files-dir ./release-files --write-draft large-draft.json --token <publisher-token> --api https://huggingbay.xyz","bay check owner/name --token <publisher-token> --api https://huggingbay.xyz","bay release owner/name --token <publisher-token> --api https://huggingbay.xyz"],"mcpTools":["get_publisher_workflow","list_publishers","get_publisher_profile","get_publisher_dashboard","apply_publisher_application","get_publisher_application_status","list_publisher_api_keys","create_publisher_api_key","revoke_publisher_api_key","create_upload_session","get_upload_session","resume_upload_session","complete_upload_session","cancel_upload_session"],"draftRequirements":["owner namespace must match the approved publisher token","sourceUrl must use HTTPS","license and provenance attestation are required","launch-ready releases should include cross-source provenance from official source, Hugging Face, ModelScope, GitHub, or a release blog when available","large releases should use upload sessions instead of inline base64 payloads","release checks must pass before public publishing"],"safety":["Do not upload gated, private, unauthorized, or license-unclear files.","Do not upload executable/high-risk files as model artifacts.","Use SHA-256 hashes and signed manifests for hosted files.","Reviewed magnet/torrent fallback metadata is public only after public visibility, source provenance, redistributable license, scan, hash, and operator review checks pass.","Keep non-Hugging Face source imports metadata-only unless an operator explicitly reviews hosting rights."],"containment":{"state":"unavailable","canonicalState":"unknown","verificationState":"unknown","executable":false,"downloadReady":false,"summary":"Canonical artifact completeness, verification, execution readiness, and download readiness are unavailable during containment."}}