Skip to main content

Public API reference

Blazium Games is the platform for playing and publishing games, applications, mods, and assets. The public API at https://api.blazium.online serves the catalog, the editor asset library, signed-out downloads, game telemetry, and build registration.

OpenAPI description​

The public endpoints are described in OpenAPI 3.1:

Load either into Swagger UI, Redocly, Postman, or a client generator. The document is also linked from the API catalog as service-desc.

Signed-in account routes (/api/v1/private/...) are used by the website and the MCP servers and are not part of it. Agents should use the developer or player MCP server instead.

Authentication​

Most public routes need no credentials. The rest take a header:

SchemeHeaderUsed by
Player key or player OAuth tokenAuthorization: Bearer ... (or the BLAZIUM_GAMES header)Optional on the editor asset library. Needs player:read.
Deploy keyX-Access-Token and X-Secret-KeyBuild registration. See Deploy builds.
Game idX-App-Id and X-Build-IdCrash and event ingest. See Crash reporting.

Player keys start with bgames_play_ and are created at blazium.games/settings/mcp. Player OAuth tokens come from https://mcp.blazium.games/.well-known/oauth-authorization-server/player. See Player MCP.

Credentials are always headers. These routes never read cookies.

Responses​

Answers use the Blazium envelope:

{ "success": true, "data": { } }
{ "success": false, "error": { "code": 4040, "message": "File not found" } }

Some errors add a top-level data object. A download that needs a sign-in or a purchase, for example, adds browse_url and the price.

The editor asset library is the exception. Its successful answers are the raw objects the Godot and Blazium editors parse, with no envelope. Its errors still use the envelope.

Common error codes​

CodeHTTPMeaning
4001401Sign in to download (or sign in and buy).
4023402Buy this game to download it.
4031403The token lacks the scope this route needs (player:read).
4033403This kind of token can't use this route.
4040404Not found, or not public.
4099409The file is still being virus-scanned.
4130413Too many events or metadata keys in one request.
5030503The download link couldn't be signed. Try again.

An invalid or expired token returns 401. It is never treated as anonymous.

Rate limits​

These limits are per IP address, per minute. Past a limit the answer is 429.

RoutesLimit
Asset library browsing (configure, asset, asset/{asset_id})300
Asset library download60
Signed-out downloads (/downloads/{file_uid} and /redirect)60
OpenAPI document120
Press kit zip30
Crash reports and events (POST)60

Shelves, tags, the sitemap, mods and tools, and press kits also have overall limits across all callers.

CORS​

The asset library, signed-out downloads, and the OpenAPI document allow any origin (Access-Control-Allow-Origin: *), without credentials. A browser tool on any site can call them.

Endpoints​

Method and pathWhat it does
GET /health, GET /readyLiveness and readiness.
GET /api/v1/public/openapi.json, .yamlThe OpenAPI document.
GET /api/v1/public/asset-library/configureEditor categories and sign-in details.
GET /api/v1/public/asset-library/assetSearch editor packages.
GET /api/v1/public/asset-library/asset/{asset_id}One editor package.
GET /api/v1/public/asset-library/asset/{asset_id}/downloadRedirect to the package zip.
GET /api/v1/public/downloads/{file_uid}A signed link for a file, without an account, when anonymous downloads are on.
GET /api/v1/public/downloads/{file_uid}/redirectThe same, answered with a redirect.
GET /api/v1/public/searchCatalog search. See Listings.
GET /api/v1/public/shelves/{kind}The tonight and unheard_of shelves.
GET /api/v1/public/tags/popularThe most used tags.
GET /api/v1/public/sitemapIndexable listings and developers.
GET /api/v1/public/store-rulesPrice limits and fees.
GET /api/v1/public/games/{game_id}A listing.
GET /api/v1/public/games/{game_id}/reviewsIts reviews.
GET /api/v1/public/games/{game_id}/relationsIts parent, dependencies, and similar titles.
GET /api/v1/public/games/{game_id}/childrenIts mods and tools.
GET /api/v1/public/games/{game_id}/press, /press.zipIts press kit.
GET /api/v1/public/games/{game_id}/files/{file_uid}/provenanceWhere a build file came from, and its scan state.
GET /api/v1/public/user/{user_id}/games/{game_id}/filesA listing's public files.
POST /api/v1/public/crashesSend a crash report.
POST /api/v1/public/eventsSend game events.
POST /api/v1/tool/upload/buildRegister a build with a deploy key.

File uploads go to uploader.blazium.online and are described in Deploy builds and the chauffeur CLI.