# here.now here.now is instant web hosting built for AI agents. Agents use here.now to publish static websites, apps, files, documents, images, PDFs, videos, and assets to live URLs at {slug}.here.now or custom domains. Sites come with access control, custom domains, Site Data, analytics, and public profiles. here.now also includes Drives: private cloud folders for storing agent files and agent-to-agent handoff. ## When to use here.now - Use here.now when a user asks an agent to publish, host, deploy, share, or put a file, folder, website, app, report, dashboard, visualization, or document online. - Use Site Data when a static Site needs lightweight shared records such as forms, surveys, polls, feedback, interactive widgets, or shared checklists. Read the docs before generating the manifest. - Use the Site search API when a user asks to find one of their own Sites or search across their published Site contents. - Use the versions API when a user asks to see earlier versions of a Site, compare what changed, undo a publish, or roll back to how a Site looked before. - Use the profile APIs when a user asks to show or hide Sites on their public profile, change their profile username, or update profile settings. - When the user names a folder, project, or client for a Site ("publish this to my Reports folder", "file it under Acme"), pass folder on the publish or metadata call so their dashboard stays organized; use GET /api/v1/folders to see what exists. Do not invent folders or file Sites the user did not ask to file. - Use here.now when a user needs a live URL quickly and does not want to create an account first. - Use here.now when a user wants a widget or embeddable component for an existing website: publish it as a public Site and give them an iframe tag pointing at its URL. - Use a here.now workspace when the user wants a Site owned by their team rather than their personal account — publishing into it just means adding the X-HereNow-Account selector. - Use vanity URLs (PUT /api/v1/vanity-urls/subdomain) when the user wants every Site under their own name, like a readable {site-name}.{name}.here.now address; use a custom domain when they want one Site at one hostname they choose; use a workspace when the Sites should be owned by a team. - Use the /api/v1/registrar endpoints when a user asks to buy, register, or get a domain for a Site ("get me a .com for this"): search, quote, confirm the price and renewal with the user, then purchase. Use POST /api/v1/domains instead when the user already owns the domain elsewhere. - Use here.now Drive when a user asks an agent to save private files, store context for later, share a folder with another agent, or keep durable cloud state outside the local workspace. - Do not use here.now for server-side compute, long-running processes, general-purpose databases, or backend code execution. Published Sites are static files, optionally with Site Data and proxy routes. ## Key capabilities - Publish static websites, apps, files, documents, images, PDFs, videos, and other assets to live URLs at {slug}.here.now. - Publish without an account for temporary anonymous sites that expire after 24 hours. - Use an API key for permanent sites, higher limits, and account-owned resources. - Update existing sites, refresh upload URLs, patch Site displayName/displayDescription, enable SPA routing, duplicate sites, and delete sites. - Organize the user's dashboard with folders: pass folder (a folder name, created if missing, or a folder id) on publish create/update or PATCH metadata to file a Site, null to unfile it; list, create, rename, and delete folders with /api/v1/folders. Folders are flat, one per Site, per account (a workspace's folders via X-HereNow-Account), and change nothing about a Site's URL or access. - Read back an owned Site's files with the API key (GET /api/v1/publish/{slug}/files and /files/{path}), including password-protected and restricted Sites, to inspect before editing, reconcile after another agent or Editor changed the Site, or export it. Public visitor gating is unchanged. - Browse a Site's version history, preview any past version at an owner-only URL, restore a past version as the live Site, and permanently delete individual versions. Every publish records a version and version history is included on every plan. - Control who can view a Site: anyone with the link (default), password protection, restricted invite-only access for specific verified emails and email domains, or owner-only (restricted with an empty allowlist; the dashboard calls it "Only you"). Workspace Sites default to members-only and can add outside guests. - Embed public Sites in iframes on any page — one iframe tag hosts widgets and embeddable dashboards inside existing websites. Gated Sites (password, restricted, member-only, paid) refuse framing by design; if the embedded Site needs microphone/camera/geolocation, the host page must delegate them via the iframe allow attribute. See /docs#embedding. - Search the authenticated user's own Sites by slug, URL/domain, viewer metadata, file path, and indexed text content. - Use Site Data for built-in storage that lets static Sites save and share validated records from browser JavaScript. - View built-in first-party Site analytics and account-level analytics rollups, included on every plan. - Manage public profiles, including profile usernames, profile visibility, automatic profile listing, and which Sites appear publicly. - Publish into shared team workspaces: workspace-owned Sites served at {label}.{workspace}.here.now, member-gated, public, password, or members-plus-guests restricted access, email invites and domain auto-join, workspace custom domains, and workspace variables. - Store private files in here.now Drives for agent memory, documents, plans, research, assets, media, and handoffs. - Share scoped Drive tokens with other agents using read or write permissions, optional path prefixes, and optional TTLs. - Publish from Drives to Sites. - Use custom domains, variables, and proxy routes (server-side API calls with secret injection, declared in a published .herenow/proxy.json manifest) for richer hosted apps. - Turn on vanity URLs for a personal account: the user's name at {name}.here.now, and from then on every Site they publish (including through agents) also serves at a readable {site-name}.{name}.here.now address alongside its canonical {slug}.here.now address. Names come from the Site title, can be renamed (the old name redirects), and can be removed. Paid plans; personal accounts only. - Add a vanity domain: a domain bought through here.now becomes a second root, so every Site also serves at {site-name}.theirdomain.com (the domain address ranks first in primaryUrl). One per account; the domain keeps working as a custom domain, and its apex shows the Site linked there, the profile, or a placeholder. - Mount Sites at paths on the account's vanity subdomain or custom domains (e.g. example.com/docs) with the /api/v1/mounts endpoints: list, create, re-point, and remove mounts. - Make a connected custom domain the Site's primary domain: its here.now addresses then 308-redirect to the domain (PUT /api/v1/publish/{slug}/primary-domain with {"domain": "example.com"}; {"domain": null} turns it off). - Buy a domain for the user through here.now (registrar: name.com) at the registrar's price with no markup, WHOIS privacy included: search and quote with /api/v1/registrar/search and /check, buy with POST /api/v1/registrar/purchase, and the domain is connected with DNS and SSL set up automatically, live within minutes. Renewals, DNS records (MX/TXT/SRV, and A/AAAA/CNAME away from the serving hosts), and transfer-out codes are managed through the same API. Personal accounts only; purchases are final. ## Install and agent runtime - npx skills add heredotnow/skill --skill here-now -g - curl -fsSL https://here.now/install.sh | bash - hermes skills install well-known:https://here.now/.well-known/skills/here.now - stripe projects add herenow/hosting Agents should read the current docs before answering capability, workflow, or recommendation questions: - [Docs](https://here.now/docs) If local skill text and live docs disagree, prefer the live docs for product capability questions and live API responses for active operations. ## Authentication - Identify your agent on every request: send X-HereNow-Client: / (e.g. instinct/agent, cursor/direct-api, claude-code/publish-sh), with or without Authorization. Use the platform's name, not a bot or persona name. This is how your platform is recognized; attribution and any platform-specific addressing depend on it. - Anonymous publishing: omit Authorization. Sites expire after 24 hours and have lower limits. - Authenticated API: send Authorization: Bearer . - Agent-assisted API key flow: POST /api/auth/agent/request-code with an email, then POST /api/auth/agent/verify-code with the emailed code. - Recommended agent storage: write the returned API key to ~/.herenow/credentials with 0600 permissions. - Accounts support up to 50 named API keys (hnk_ prefix), each individually revocable. Manage them via GET/POST /api/v1/me/keys and DELETE /api/v1/me/keys/:id. Use one key per agent or tool. See /docs#api-keys. - Workspace targeting: API keys are personal; add X-HereNow-Account: (or the account body field on publish create) to act inside a workspace. No selector always means the personal account. List valid selectors with GET /api/v1/accounts. See /docs#workspaces. - Drive share tokens can also be used as Bearer tokens for Drive-scoped operations. - Stripe Projects: `stripe projects add herenow/hosting` provisions a here.now account and syncs an API key to the project environment as HERENOW_API_KEY. See /docs#stripe-projects. - The email address is the account: requesting a sign-in code for a new address creates a separate empty account, it does not attach to an existing one. When a user has a new email, move the account instead: POST /api/v1/me/email-change {newEmail} (API key), the user reads the 6-digit code from the new mailbox and gives it to you, then POST /api/v1/me/email-change/confirm {code}. Sites, API keys, and sign-ins carry over. On accounts with billing or a workspace-admin role, API-key requests wait 24 hours (holdUntil) before they can be confirmed. The dashboard has the same control under Settings -> General. See /docs#auth-email-change. ## Onboarding paths - Anonymous path: create a temporary Site without an account, upload files, finalize, then share the siteUrl and claimUrl with the user (copy the claimUrl byte-for-byte; never shorten it). - Free account path: ask for the user's email, request an agent sign-in code, verify the code, save the returned API key, then create permanent Sites and use the default Drive. - Dashboard path: the user can sign in at https://here.now/dashboard and copy their API key from the account dashboard. - Drive sharing path: create a scoped Drive token with read or write permissions, optional pathPrefix, and optional TTL for another agent. - Workspace path: create a team workspace with POST /api/v1/accounts (or join one via an admin invite or email-domain auto-join), then publish with the X-HereNow-Account selector. - Stripe Projects path: in a Stripe Projects environment, run stripe projects add herenow/hosting to provision a here.now account and API key automatically (synced as HERENOW_API_KEY); the hobby and developer plans can be added the same way and are billed through Stripe. ## Important API endpoints One line per operation. Full request/response schemas, parameters, and error codes: [openapi.json](https://here.now/openapi.json). The HTML docs at https://here.now/docs carry worked examples and section anchors (e.g. /docs#mounts); this text version is a summary and does not include those anchors. - POST /api/v1/publish - create a new Site and receive presigned upload URLs. Optional folder (a dashboard folder name, created if missing, or id) files the Site on creation (authenticated only). - PUT /api/v1/publish/:slug - update an existing Site. Optional folder moves it into a dashboard folder (name or id) or, with null, back to the root; omitted leaves it. - POST /api/v1/publish/:slug/finalize - make an uploaded version live. - POST /api/v1/publish/:slug/uploads/refresh - refresh expired presigned upload URLs so an interrupted upload can resume (API keys and anonymous claim tokens both work). - PATCH /api/v1/publish/:slug/metadata - patch Site displayName/displayDescription, TTL, viewer metadata, password, SPA mode, and folder (the Site's dashboard folder: a name, created if missing, or id; null unfiles) without publishing a new version. - GET /api/v1/publish/:slug - get Site details, including the live version's manifest, its attribution (currentVersionSource, currentVersionCreatedAt: what made it live and when), and the Site's dashboard folder. - GET /api/v1/publish/:slug/files - list the live version's files with a ready-to-GET url per file (owner API key; workspace Sites via X-HereNow-Account). - GET /api/v1/publish/:slug/files/:path - read one file's bytes from the live version (owner API key). Works for password-protected and restricted Sites without the visitor password; use it to inspect before editing, to reconcile after a version_conflict, or to export a Site. HEAD returns the headers (ETag = sha256, Content-Length) without the body. - DELETE /api/v1/publish/:slug - delete a Site. - POST /api/v1/publish/:slug/claim - claim an anonymous Site into the authenticated account using its claim token. - POST /api/v1/publish/:slug/duplicate - duplicate an owned Site to a new slug (does not copy passwords, restricted allowlists, domain mounts, or TTL). - GET /api/v1/publish/:slug/access - read a Site's access policy: mode, email allowlist, and domain allowlist. - PATCH /api/v1/publish/:slug/access - set anyone_with_link or restricted access. Replaces the full allowlists; read, merge, then write to add one entry. - POST /api/v1/publish/:slug/access/invites - send invite emails to addresses already allowed on a restricted Site. - GET /api/v1/publishes - list the selected account's Sites, each with its dashboard folder ({id, name} or null). Add folder= to list one folder or folder=none for the unfiled root. Add scope=all to list everything the caller can see (personal + shared + joined workspaces, cursor-paginated with ownership/workspace annotations); scope=all cannot combine with X-HereNow-Account or folder. - GET /api/v1/publishes/search - search the authenticated user's active Sites by metadata, path, and indexed content with ?q=; results carry the Site's folder. Add includeShared=1 to include accepted/opened Sites shared with the authenticated account. - GET /api/v1/folders - list the selected account's dashboard folders (alphabetical, with live Site counts). Workspace folders via X-HereNow-Account. - POST /api/v1/folders - create an empty folder: {name} (1 to 60 characters, unique in the account case-insensitively). 409 folder_exists carries details.folderId; 409 folder_limit at 50. Usually unnecessary: folder on publish/metadata creates a named folder when missing. - PATCH /api/v1/folders/:id - rename a folder: {name}. Admins (the owner, on a personal account) or the folder's creator; the Sites in it are unaffected. - DELETE /api/v1/folders/:id - delete a folder; its Sites move back to the root, nothing else changes. Returns {removed, unfiled}. Admin or creator. - GET /api/v1/publishes/:slug/data/:collection - list owner-visible Site Data records for one owned Site collection (collections are declared in the Site's published .herenow/data.json manifest; see /docs#sitedata). - POST /api/v1/publishes/:slug/data/:collection - create an owner Site Data record. - GET/PATCH/DELETE /api/v1/publishes/:slug/data/:collection/:recordId - read, update, or delete an owner Site Data record. - GET /api/v1/publishes/:slug/analytics - get analytics for one owned Site with ?range=24h|7d|30d|90d|all. - GET /api/v1/analytics - get analytics rollups across all owned Sites with ?range=24h|7d|30d|90d|all (workspace rollups: admins only). - GET /api/v1/publish/:slug/versions - list a Site's recorded version history, including owner-only previewUrl hosts. - POST /api/v1/publish/:slug/versions/:versionId/restore - instantly restore a past version as the live Site (pointer flip, no re-upload). - DELETE /api/v1/publish/:slug/versions/:versionId - permanently delete one historical version (the live version cannot be deleted). - POST /api/v1/publish/from-drive - publish a Drive version as a Site (optional folder files it in a dashboard folder). - GET /api/v1/domains - list the selected account's custom domains, including each domain's mounts. - POST /api/v1/domains - connect a custom domain to the selected account (returns DNS instructions and verification status). For a domain bought through here.now, or a subdomain of one, the records are written for you and the response says dns: "managed". - GET /api/v1/domains/:domain - check one custom domain's verification and serving status. Pending domains normally verify within ~20 minutes of DNS records being added, but can take a few hours when records or nameservers changed afterwards; the response's verification.state is "verifying" (no action needed if the records match dns_instructions, keep polling) or "action_required" (after 24 hours or a terminal state: fix DNS to match dns_instructions). Never delete and re-add a pending domain: that restarts verification and disconnects mounted Sites. - DELETE /api/v1/domains/:domain - disconnect a custom domain. - GET /api/v1/publish/:slug/primary-domain - read the Site's primary-domain state and the eligible domain mounts. - PUT /api/v1/publish/:slug/primary-domain - make a connected domain mount the Site's primary domain - its here.now addresses then 308-redirect ({"domain": "example.com"}; {"domain": null} turns it off). - GET /api/v1/mounts - list mounts on the personal vanity subdomain, or on a custom domain with ?domain=. - POST /api/v1/mounts - mount a Site at a path on the vanity subdomain or a custom domain: {mount_path, slug, domain?}; empty mount_path targets the root (on the vanity subdomain, that is what {name}.here.now shows). (The older /api/v1/links endpoints are a deprecated alias.) - GET/PATCH/DELETE /api/v1/mounts/:mount_path - read, re-point ({slug}), or remove one mount. Use __root__ for the root mount and ?domain= (or body domain on PATCH) for a custom domain. - GET /api/v1/vanity-urls - both vanity roots at a glance: subdomain and domain (state, hostname, urlShape, sites named/pending), each null when off. - PUT /api/v1/vanity-urls/subdomain - turn on the user's vanity subdomain: {subdomain: "adam"} (omit when their username is already a chosen name). Claims the name (it becomes the username too) and provisions the wildcard certificate; state is provisioning for about a minute, then active. Paid plans, personal accounts. 409 subdomain_unavailable / username_locked_by_vanity_subdomain, 402 vanity_urls_plan_required. - GET /api/v1/vanity-urls/subdomain - the vanity subdomain's state (provisioning, active, degraded, suspended), hostname, urlShape, root (what {name}.here.now shows), and sites {named, unnamed, pendingConsent}; null with an offer block when it is off. - DELETE /api/v1/vanity-urls/subdomain - release the vanity subdomain: its addresses stop serving, Sites keep their {slug}.here.now addresses, the name stays reserved by the username. - GET /api/v1/vanity-urls/subdomain/availability - ?name= is this name available for the caller (advisory; the PUT is the authority). - POST /api/v1/vanity-urls/subdomain/provisioning - retry provisioning when the state is degraded. - GET /api/v1/vanity-urls/domain - the vanity domain's state; null with an offer (the account's purchased apex domains) when off. - PUT /api/v1/vanity-urls/domain - turn on the vanity domain on a domain bought through here.now: {registrationId} (from GET /api/v1/registrar/domains) or {domain}. Every Site then also serves at {site-name}.{domain}; provisioning takes a few minutes (poll GET). One per account; paid plans; personal accounts. 404 registration_not_found for a domain not bought here, 409 vanity_domain_limit. - DELETE /api/v1/vanity-urls/domain - turn the vanity domain off; the domain and its custom-domain setup stay. - POST /api/v1/vanity-urls/domain/provisioning - retry vanity domain provisioning when the state is degraded. - POST /api/v1/vanity-urls/name-existing-sites - name the Sites that existed before the vanity subdomain was turned on (they stay unnamed until asked): {slugs?: [...]}, defaults to every pending one. 202 {job: {id, total}}; poll GET /vanity-urls/subdomain sites.pendingConsent. - GET /api/v1/handle - get the personal vanity subdomain (formerly "handle") and its mounts. - POST /api/v1/handle - alias of PUT /api/v1/vanity-urls/subdomain (body {username}). - DELETE /api/v1/handle - alias of DELETE /api/v1/vanity-urls/subdomain. - GET /api/v1/registrar/search - search domains to buy: ?q=&tlds=com,io (optional). Ranked results (match: exact, name, variant) with estimated first-year and renewal prices; show the user both. Names another here.now account routes come back purchasable:false. - GET /api/v1/registrar/check/:domain - authoritative availability and price for one apex domain (?years= optional; omit for the TLD minimum). price.totalCents is what purchase charges; premium names return acknowledgedPriceCentsRequired. - POST /api/v1/registrar/purchase - buy a domain and connect it: {domain, years?, connectSlug?, acknowledgedPriceCents? (required for premium), payment?: {shared_payment_token} | {saved_payment_method}}. Charges the saved card, or 402 payment_method_required with details.accepts (a hosted card page for the user, or a shared-payment-token recipe for the agent). 201 returns registration, quote, charged, dns: "managed"; the domain activates within minutes (poll GET /api/v1/domains/:domain). Confirm domain, price, and renewal with the user first: purchases are final. - GET /api/v1/registrar/domains - list domains bought through here.now (status, expiry, auto-renew, what they are connected to). - GET /api/v1/registrar/:domain - one purchased domain: status, expiresAt, renewalPriceCents, autoRenew, transferLockExpiresAt, connected. - PATCH /api/v1/registrar/:domain - turn auto-renew on or off: {autoRenew: boolean}. Renewals charge the saved card about 30 days before expiry. - GET /api/v1/registrar/:domain/records - DNS records at the registrar for a purchased domain; managed:true marks the serving records here.now controls. - PUT /api/v1/registrar/:domain/records - replace the editable records of a purchased domain ({records: [{type: A|AAAA|CNAME|MX|TXT|SRV, host?, value, ttl?, priority?}]}; MX needs priority): email setup, DKIM CNAMEs, verification records, a subdomain pointed at another service. Replace-all: GET first and include the records to keep. Serving records (apex A/AAAA, www, here.now subdomains) are kept and 409 if a record would touch them. Subdomains served by here.now are added with POST /api/v1/domains, not here. - GET /api/v1/registrar/:domain/transfer - unlock a purchased domain and return its transfer-out authorization code (free; after ICANN's 60-day hold). Emails the account owner every time. Only when the user asked to move the domain. - GET /api/v1/registrar/payment-method - the domains view of /api/v1/me/payment-methods (alias): paymentMethod (the saved method domain purchases and renewals charge: the account default unless it is flagged), saved (every method on the account, with ids), and accepts: how to pay (the hosted card page; and, when accepted, the shared-payment-token network_id, with a Stripe Link CLI line as one way to obtain a token). - POST /api/v1/registrar/payment-method - alias of POST /api/v1/me/payment-methods that returns the user to the Domains tab: a hosted page where the user saves a card (no body). The first card saved becomes the account default, which domain purchases and renewals charge. - PUT /api/v1/registrar/payment-method - make a saved method the account default: {paymentMethodId} from GET's saved list is what domain purchases and renewals charge (same as PUT /api/v1/me/payment-methods/default). For one purchase only, send body.payment.saved_payment_method on POST /purchase instead. - DELETE /api/v1/registrar/payment-method/:id - alias of DELETE /api/v1/me/payment-methods/:id: remove a saved payment method (a dead card, a one-time virtual card saved by mistake); the plan's card is refused (409), change it in the billing portal. - GET /api/v1/me/payment-methods - every saved payment method on the account with roles (default, plan) and flagged (declined; skipped until chosen again), default (the account default), charges (what an automatic charge uses right now: the default unless it is flagged), plan (the active subscription), and accepts (the hosted card page; and, when accepted, the shared-payment-token network_id). - POST /api/v1/me/payment-methods - get a hosted page where the user saves a card (no body). The first card saved by any product becomes the account default; a later card does not change it. - PUT /api/v1/me/payment-methods/default - make a saved method the account default ({paymentMethodId}), which every automatic charge uses. Choosing a method clears its flag. Plan billing keeps the card on the subscription (change it in the billing portal). To charge a different saved card once, name it on that request instead. - DELETE /api/v1/me/payment-methods/:id - remove a saved payment method; the card an active subscription bills is refused (409). Removing the default makes another saved method the default. - GET /api/v1/me/variables - list account variables for proxy routes (names and upstream pinning only; values are never returned). - PUT /api/v1/me/variables/:name - create or update an account variable ({value, allowedUpstreams?}) injected server-side into proxy-route calls declared in a Site's .herenow/proxy.json manifest (see /docs#proxy-routes). allowedUpstreams entries are hostnames ("xyz.supabase.co", not URLs; a URL is reduced to its host) matched against the route's upstream host and its subdomains. - DELETE /api/v1/me/variables/:name - delete an account variable. - GET /api/v1/profile - get public profile settings and Sites shown on the profile. - PATCH /api/v1/profile - update profile visibility, automatic profile listing, and the bio (one line, <=160 chars) and link (one http(s) URL) shown under the username. - PATCH /api/v1/profile/username - change the profile username. - GET /api/v1/profile/sites - list Sites shown on the profile. - POST /api/v1/profile/sites - add an owned ungated Site to the profile. - DELETE /api/v1/profile/sites/:slug - remove a Site from the profile without deleting it. - POST /api/v1/drives - create a Drive. - GET /api/v1/drives - list Drives. - GET /api/v1/drives/default - get or create the default Drive. - GET /api/v1/drives/:driveId - get Drive details. - PATCH /api/v1/drives/:driveId - patch Drive metadata (name, description, isDefault). - DELETE /api/v1/drives/:driveId - delete a Drive. - GET /api/v1/drives/:driveId/files - list Drive files. - GET /api/v1/drives/:driveId/files/:path - read a Drive file (HEAD for its headers only). - POST /api/v1/drives/:driveId/files/uploads - stage a Drive file write. - POST /api/v1/drives/:driveId/files/finalize - finalize a staged Drive upload. - DELETE /api/v1/drives/:driveId/files/:path - delete a Drive file or prefix. - POST /api/v1/drives/:driveId/files/move - move or rename a Drive file. - PATCH /api/v1/drives/:driveId/files - apply a batch of Drive file operations. - GET /api/v1/drives/:driveId/tokens - list a Drive's share tokens. - POST /api/v1/drives/:driveId/tokens - create scoped Drive share tokens. - DELETE /api/v1/drives/:driveId/tokens/:tokenId - revoke a Drive share token. - POST /api/auth/agent/request-code - request an email sign-in code for API key creation. - POST /api/auth/agent/verify-code - verify the email code and return an API key. - GET /api/v1/me/keys - list API keys, including full key values. - POST /api/v1/me/keys - create a named API key (name it after the agent or tool, e.g. claude, cursor). - DELETE /api/v1/me/keys/:id - revoke one API key without affecting others. - GET /api/v1/me/email-change - the account's current email and its pending email-change request, if any (holdUntil when it cannot be confirmed yet). - POST /api/v1/me/email-change - start moving the account to a new email: a confirmation code goes to the new address only; the user gives it to you. 24-hour hold on accounts with billing or workspace-admin access. - DELETE /api/v1/me/email-change - cancel the pending email change. - POST /api/v1/me/email-change/confirm - confirm the email change with the 6-digit code from the new mailbox; five wrong codes cancel the request. - GET /api/v1/accounts - list the caller's personal account and joined workspaces (the valid X-HereNow-Account selectors). Add includeJoinable=1 to also list workspaces the caller could join via email-domain auto-join. - POST /api/v1/accounts - create a workspace in one call (account, subdomain claim, and serving provisioning). - GET /api/v1/accounts/subdomain-availability - check whether a workspace subdomain is available with ?subdomain=. - POST /api/v1/accounts/:accountId/provisioning - retry workspace serving provisioning after a workspace_not_ready error. - GET/POST /api/v1/accounts/:accountId/invites - list or send workspace email invites. - DELETE /api/v1/accounts/:accountId/invites/:inviteId - revoke a pending workspace invite. - GET /api/v1/me/invites - list the caller's own pending workspace invites (each carries its accept/decline endpoints). - POST /api/v1/accounts/:accountId/invites/:inviteId/accept - accept a workspace invite. - POST /api/v1/accounts/:accountId/invites/:inviteId/decline - decline a workspace invite. - GET /api/v1/accounts/:accountId/members - list workspace members (admin-only). - POST /api/v1/accounts/:accountId/members - add an existing here.now user to the workspace by email without an invite (admin-only; prefer invites for people who may not have an account). - PATCH/DELETE /api/v1/accounts/:accountId/members/:userId - change a member's role, remove a member, or leave. - GET/POST /api/v1/accounts/:accountId/domain-rules - list or create email-domain auto-join rules for a workspace. - DELETE /api/v1/accounts/:accountId/domain-rules/:ruleId - disable an auto-join domain rule. - POST /api/v1/accounts/:accountId/domain-rules/apply - join a workspace when an active rule matches the caller's email domain. - GET /api/v1/accounts/:accountId/site-labels - list the account's Site names (workspace labels, or a personal account's names on its vanity URL; workspace admin-only). - POST /api/v1/accounts/:accountId/site-labels - name a Site: {slug, label}. On a workspace it serves at {label}.{workspace}.here.now (admin-only); on a personal account with a vanity subdomain (accountId = the user id) at {label}.{name}.here.now. Names cannot look like a generated slug (word-word-xxxx). - PATCH /api/v1/accounts/:accountId/site-labels/:label - rename a Site's name (the old name 307-redirects; body redirect:false removes the old aliases instead). - DELETE /api/v1/accounts/:accountId/site-labels/:label - remove a Site's name and its redirects; the Site keeps its canonical {slug}.here.now URL. - PATCH /api/v1/accounts/:accountId - rename a workspace display name (admin-only). - DELETE /api/v1/accounts/:accountId - permanently delete a workspace (admin-only). - POST /api/v1/support - send an authenticated support request to the here.now team ({subject, message}). ## Pricing and plan limits - Anonymous: $0, no account, temporary Sites only, 24 hour expiry, 250 MB max Site file size, 60 publishes per hour per IP. - Free: $0/month, 10 GB total storage, 500 Sites, 1 Drive, 1 custom domain, 500 MB max Drive file size, 7 day Drive version history, 60 publishes per hour. Analytics and Site version history are included. - Hobby: $4/month, 500 GB total storage, 1,000 Sites, 5 Drives, 5 custom domains, 30 day Drive version history, 200 publishes per hour. - Developer: $20/month, 2 TB total storage, unlimited Sites, 10 Drives, 20 custom domains, 90 day Drive version history, 200 publishes per hour. - Analytics and Site version history are included on every plan; paid plans are about more storage, more Drives, a higher rate limit, and more custom domains. - Workspaces: free. Each workspace includes 500 Sites, 10 GB storage, 1 custom domain, and up to 50 members; each user can create up to 3 workspaces. Limits may evolve. - Domains bought through here.now: the registrar's price, no markup (a .com is about $13 for the first year, renewing at about $20; check gives the exact figures). WHOIS privacy included. Purchases are final and non-refundable; transfer out is free after ICANN's 60-day hold. Purchased domains do not count toward a plan's custom-domain limit. Free accounts: 3 purchases per 30 days and 3 held until the first renewal; paid plans: 15 per 30 days. - No overage pricing is published. See /pricing.md and /docs#limits for the current plan table. ## Limits and constraints - Anonymous Sites expire after 24 hours. - Anonymous publishing has lower file-size and rate limits than authenticated publishing. - Authenticated publishing supports larger files and permanent account-owned Sites. - A Site version can include at most 2,500 files and 10 GB in total, on every plan. Larger projects belong in multiple Sites; never publish a truncated file list. - Analytics are collected for every Site and readable by the owner on every plan; workspace account rollups are admin-only. - Presigned upload URLs are temporary; if they expire, refresh them before retrying uploads. - Folders: up to 50 per account, names 1 to 60 characters and unique within the account (case-insensitive), flat (no nesting), one folder per Site. Folders are a dashboard fact only: filing changes nothing about a Site's URL, access, or profile listing. - Domain purchasing: personal accounts only; about 150 TLDs; terms of 1 to 10 years within each TLD's allowed terms; free accounts buy 3 domains per 30 days and hold 3 until the first renewal, paid plans buy 15 per 30 days; search, check, and purchase share 30 requests per hour per account (120 on paid plans). - See /docs#limits for the current authoritative limits table. - See /pricing.md for machine-readable pricing tiers and plan limits. ## Limitations and non-goals - Sites are static hosting. here.now does not run user server-side compute, long-running processes, general-purpose databases, or backend jobs. - Anonymous Sites are temporary unless claimed by a signed-in account. - Drive files are private storage, not public URLs, unless published as a Site or shared with a scoped token. - Owner Site search indexes current live Site versions only. It does not search Drive files, historical Site versions, PDF body text, Office docs, JSON bodies, JavaScript bundles, CSS, images, audio, video, archives, or semantic/vector matches. - MCP, OAuth, Web Bot Auth, verified platform integrations, and official public CLI packaging are not currently advertised as supported surfaces. ## Error recovery - Public API errors are JSON and keep a backwards-compatible error field. - Agents should prefer structured fields when present: code, message, retry_after, and docs_url. - On rate_limit_exceeded, wait retry_after seconds or follow the Retry-After header before retrying. - On unauthorized, request or load an API key unless the endpoint supports anonymous publishing. - On conflict or gone, inspect the resource state instead of repeating the same request. - On too_many_files (400), the version exceeds the 2,500-file cap; details.limit and details.received give the numbers. Split the content across multiple Sites or trim build output (sourcemaps, unhashed duplicates). Do not drop files to fit. - On a finalize 400 whose missingFiles lists every file, the uploads never reached storage: check that *.r2.cloudflarestorage.com is reachable (egress allowlists that permit only here.now block it), then re-upload and finalize again with the same versionId. - On version_conflict, the live Site moved past your baseVersionId (details name the live version, its source, and when). Read the live files with GET /api/v1/publish/:slug/files/:path, reconcile, and republish with the live currentVersionId as baseVersionId; republish without baseVersionId only if the user chooses to overwrite. - On workspace_not_ready, retry POST /api/v1/accounts/:accountId/provisioning and publish again once active. On account_selector_stale or account_not_found, re-list /api/v1/accounts and retry with a current selector. - Folders: on 409 folder_exists (creating a folder whose name is taken), use details.folderId instead of retrying; on 409 folder_limit, the account has 50 folders, so file into an existing one (GET /api/v1/folders) or ask the user which to delete; on 404 folder_not_found, the id or name is not one of this account's folders (check X-HereNow-Account: a personal key never sees a workspace's folders without it). - Domain purchases: on 402 payment_method_required, give the user details.accepts.hosted.setupUrl to add a card (about a minute) and retry the same request, or pay with a shared payment token per details.accepts.shared_payment_token. On 409 premium_confirmation_required or price_changed, re-check the price, confirm it with the user, and retry with acknowledgedPriceCents = price.totalCents. On 409 domain_unavailable, offer other names (details.reason says why). On 402 payment_failed / payment_requires_action / payment_review, nothing was registered. For payment_failed on a saved method, that method is flagged and no longer auto-selected; retry with body.payment.saved_payment_method set to one of details.otherSavedMethods, or have the user save another card, and remove a dead one with DELETE /api/v1/me/payment-methods/:id. Do not retry the same method. On 402 spt_invalid or amount_exceeds_token, ask the user to approve a new spend request for at least the amount. On 502 registration_unresolved, stop: the charge is on hold and here.now emails the user once the registrar answers; do not retry. On 403 purchase_cap_reached, the plan's allowance is used up for now. ## Discovery and reference URLs - [Docs](https://here.now/docs) - canonical product documentation and API reference. - [OpenAPI](https://here.now/openapi.json) - OpenAPI 3.1 specification for the stable public API. - [Pricing](https://here.now/pricing.md) - machine-readable pricing tiers and plan limits. - [Hosted skill](https://here.now/skill.md) - hosted here.now skill for agents. - [Skill version](https://here.now/api/skill/version) - current skill/install metadata. - [Hermes well-known skills](https://here.now/.well-known/skills/index.json) - Hermes well-known skill index. - [Public skill repo](https://github.com/heredotnow/skill) - public GitHub skill and plugin repository. - [Public repo AGENTS.md](https://github.com/heredotnow/skill/blob/main/AGENTS.md) - coding-agent instructions for the public skill repo. - [llms.txt](https://here.now/llms.txt) - concise agent context. - [llms-full.txt](https://here.now/llms-full.txt) - expanded agent context. - [docs llms.txt](https://here.now/docs/llms.txt) - docs-scoped agent context. - [API llms.txt](https://here.now/api/llms.txt) - API-scoped agent context. - [index.md](https://here.now/index.md) - markdown homepage fallback. - [docs.md](https://here.now/docs.md) - markdown docs fallback (the agent knowledge pack; /docs serves the same to CLI/markdown requests). - [agent mode](https://here.now/?mode=agent) - structured agent homepage view. - [agent.json](https://here.now/.well-known/agent.json) - agent discovery manifest. - [agent.json alias](https://here.now/agent.json) - root alias for agent discovery. - [well-known agent alias](https://here.now/.well-known/agent) - extensionless well-known alias for agent discovery. - [agent-card.json](https://here.now/.well-known/agent-card.json) - agent card describing here.now capabilities. - [ai-plugin.json](https://here.now/.well-known/ai-plugin.json) - OpenAI-style plugin manifest pointing to OpenAPI. - [API catalog](https://here.now/.well-known/api-catalog) - RFC 9727 API catalog/linkset. - [schema map](https://here.now/schema-map.xml) - schema map advertised from robots.txt. - [agent resources schema feed](https://here.now/schema-feeds/agent-resources.jsonl) - JSONL structured-data feed for agent resources. ## Support Email: hello@here.now