# Deploy

> One request turns a folder of files into a URL somebody can open on a phone. No build step, no bundler, no configuration.

A folder of static files becomes an address. The bytes your agent sends are the bytes that get served.

```
curl -sS -X POST https://api.superart.page/deploy \
  -H "Authorization: Bearer $SUPER_ARTIFACTS_KEY" \
  -H "Content-Type: application/json" \
  -d @deploy.json
```

## What goes over the wire

JSON: a slug, a sentence of metadata saying why the thing was built, and the files base64-encoded. Each file may carry the SHA-256 of its own decoded bytes, which the server recomputes and refuses on a mismatch, so a truncated upload fails at deploy time rather than quietly serving a corrupt page.

The response carries the artifact's id, the version just written, and the URL. Copy that URL field exactly: renderers glue adjacent characters onto a link, including invisible ones, and a zero-width space on the end of a perfectly good address is a 404 somebody has already tapped.

## Why an endpoint and not a bucket

No storage access keys exist for this account, and with an endpoint none ever need to. The worker already holds a native binding to the bucket, so the only credential in play authorises deploying rather than raw bucket access. A deploy key scoped to one account's own artifacts and revocable from a dashboard is a much smaller thing to lose than a storage key.

## What it will not do for you

There is no build. If your agent wrote TypeScript, your agent compiles it. A build step on this side would mean running somebody else's toolchain against somebody else's dependencies, and the product's whole shape is that no user-authored code runs on the platform.

It also will not write the artifact. The platform runs no inference anywhere; every byte comes out of your agent's model, on your tokens.

Read the [deploy guide](https://superartifacts.app/docs/deploy-an-artifact.md) and the [deploy contract](https://superartifacts.app/docs/deploy-contract.md).

## The rest of it

- [Versions](https://superartifacts.app/features/versions.md): Publishing moves a pointer at an immutable version. Rolling back and rolling forward are the same operation.
- [Access](https://superartifacts.app/features/access.md): Artifacts are private by default. Sharing is an explicit grant, enforced by a signature the serving worker verifies.
- [Analytics](https://superartifacts.app/features/analytics.md): Whether anyone read an artifact, on what, and whether it threw an error while they did. The visitor address is never stored, only hashed.
- [Agents](https://superartifacts.app/features/agents.md): Install what the harness expects, one key from the dashboard, and the agent deploys on its own, including agents with no shell.
