← Docs

API reference

NuGet feed endpoints and private-feed credential automation.

1. NuGet feed endpoints

Feed-backed offerings expose a NuGet v3 source at this URL:

https://www.pkgstore.io/api/nuget/{publisherSlug}/{productSlug}/index.json

NuGet clients use basic authentication with a generated restore username and password. Push uses the feed URL without /index.json and the feed push key as the API key.

Method Path Purpose
PUT /api/nuget/{publisher}/{product} Push a .nupkg with a NuGet API key.
GET /api/nuget/{publisher}/{product}/index.json NuGet v3 service index for restore.
GET /api/nuget/{publisher}/{product}/search/query Search packages visible to the credential.
GET /api/nuget/{publisher}/{product}/flatcontainer/... Package version and download endpoints used by NuGet clients.

Symbol packages are not supported by a symbol server endpoint.

2. Credentials API

The Credentials API is available for Private Feed offerings only. Use the feed push key in the X-API-Key header. It creates, lists, and revokes restore credentials for private-feed automation.

Method Path Result
POST /api/nuget/{publisher}/{product}/credentials Creates a credential and returns the password once.
GET /api/nuget/{publisher}/{product}/credentials Lists credential ids, usernames, labels, and creation times.
DELETE /api/nuget/{publisher}/{product}/credentials/{id} Revokes the credential.

3. Examples

curl -X POST "https://www.pkgstore.io/api/nuget/acme/toolkit/credentials" \
  -H "X-API-Key: YOUR_PUSH_KEY" \
  -H "Content-Type: application/json" \
  -d "{\"label\":\"ci-agent-01\"}"
curl "https://www.pkgstore.io/api/nuget/acme/toolkit/credentials" \
  -H "X-API-Key: YOUR_PUSH_KEY"

curl -X DELETE "https://www.pkgstore.io/api/nuget/acme/toolkit/credentials/123" \
  -H "X-API-Key: YOUR_PUSH_KEY"

Need manual access control?

Use dashboard controls for most credential work, and the API for automation.

Manage access
đź’ˇ Feedback