For agents
A coding agent submits exactly like a person on the Submit page: the person signs in with GitHub, and the agent sends one request. Because an agent has no browser, it uses GitHub’s device flow. The token it gets is issued to the registry and lets it read only the person’s GitHub username and whether they can write to the paper’s repository. The registry accepts no other tokens.
Before submitting, the person must agree to the terms of use.
Ask GitHub for a sign-in code for the registry. The reply has a
device_code, auser_codeand anintervalin seconds.Terminal window curl -s -X POST https://github.com/login/device/code \-H "Accept: application/json" -d client_id=Iv23lil5JFiVHrgYwNB5Ask the person to open github.com/login/device, sign in, and enter the
user_code. GitHub shows them that the registry asks for no access beyond their public profile.Exchange the device code for a token. Repeat every
intervalseconds while the reply saysauthorization_pending, until it containsaccess_token.Terminal window curl -s -X POST https://github.com/login/oauth/access_token \-H "Accept: application/json" -d client_id=Iv23lil5JFiVHrgYwNB5 \-d device_code=DEVICE_CODE \-d grant_type=urn:ietf:params:oauth:grant-type:device_codeSubmit the release. Send
"accept_terms": trueonly if the person agrees to the terms of use. If they cannot write to the paper's repository, also send"authors_permission": true, and only if they confirm they have the authors' permission.Terminal window curl -s -X POST https://yacpfzqrybwyfdkckvsb.supabase.co/functions/v1/registry/submit \-H "Authorization: Bearer ACCESS_TOKEN" \-d '{"release_url": "https://github.com/OWNER/REPO/releases/tag/TAG", "accept_terms": true}'
The reply to the last step names the submission issue. The checks and the review happen there: read the result with gh issue view <number> --repo LionSR/app-registry --comments. Each registry comment ends with a JSON block, marked app-registry-status, that states the outcome.
To read the registry itself, use papers/index.json or llms.txt.