Platform controls
Configure media behavior, automation, migration, and company access through workspace-scoped APIs.
Regional policy
PUT/api/platform/delivery-policy
200 OKAllow or deny delivery countries and read the workspace's active storage region.
Required scopeworkspace:admin
{
"mode": "deny",
"countries": ["KP", "RU"]
}
Country rules fail closed unless requests come through a trusted edge carrying SteadyLink country and policy headers.
Set a focal point
PUT/api/platform/assets/{asset_id}/focal-point
200 OKSet the default crop position for cover transforms.
Required scopeassets:write
POST/api/platform/migrations
201 CreatedCreate up to 100 presigned upload sessions while retaining each manifest path.
Required scopeassets:write
Webhooks and channel notifications
POST/api/platform/webhooks
201 CreatedRegister a custom HTTPS receiver or a Discord, Slack, or Teams destination.
Required scopeworkspace:admin
{
"url": "https://app.example.com/hooks/steadylink",
"destinationType": "generic",
"events": ["asset.revision.published", "asset.scan.completed"]
}
{
"url": "https://discord.com/api/webhooks/...",
"destinationType": "discord",
"events": ["asset.scan.completed"]
}
Custom receivers get the original JSON and HMAC headers. Native channel URLs are encrypted and receive provider-specific message payloads instead. SteadyLink retries failed deliveries without creating duplicate event IDs.
Encrypted originals and SSO
Workspace encryption protects newly committed originals before storage. Existing revisions are unchanged when the setting changes.
PUT/api/platform/sso
200 OKConfigure an OpenID Connect issuer, allowed email domains, and workspace enforcement.
Required scopeworkspace:admin
Save and enable the connection, use its test login URL, then enforce it. The API rejects enforcement until that provider completes a valid login.