HTMLDrop.
REST API

A playground with an API.

The editor and automation share the same public guest project model. All endpoints return JSON.

Create a project

curl -X POST http://localhost:3000/api/v1/projects \
  -H "Content-Type: application/json" \
  -d '{"template":"aurora","title":"My experiment"}'

Read and edit

GET a project to retrieve its state and revision. PATCH accepts metadata and/or a complete state. Source updates require the current revision to prevent overwriting concurrent edits. Guest hashes cannot be renamed, deleted, claimed, or made private through the API.

GET   /api/v1/projects/{slug}
PATCH /api/v1/projects/{slug}

{
  "revision": "revision-from-GET",
  "state": {
    "html": "<h1>Hello</h1>",
    "css": "h1 { color: seagreen; }",
    "javascript": "console.log(42)",
    "javascriptMode": "module",
    "headers": { "Access-Control-Allow-Origin": "*" }
  }
}

Versions, restores, and forks

POST /api/v1/projects/{slug}/versions
GET  /api/v1/projects/{slug}/versions
GET  /api/v1/projects/{slug}/versions/1
POST /api/v1/projects/{slug}/restore  {"version":1}
POST /api/v1/projects/{slug}/fork     {"version":1}
GET  /api/v1/projects/{slug}/export

Limits and errors

Each source file may contain up to 1 MB of UTF-8 text. Up to 32 custom headers are accepted. Mutations are rate limited; project creation is limited to 20 requests per IP per minute. Error responses use a message field. 409 indicates a stale revision or duplicate version, and 429 indicates a rate limit.

API origin policy

Browser mutations are limited to the configured application origin. CLI and MCP requests without an Origin header are accepted. There are no authentication tokens for guest projects: editor URLs deliberately grant collaborative access.

Made to be explored. Open the workspace and try it for yourself.