How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Primitive Functions API

Deploy JavaScript handlers that run on inbound mail. Each functionis a single ESM module whose default export is an object with anasync `fetch(request, env)` method, in the shape of a Workers-stylehandler. Primitive signs each delivery and forwards the`Primitive-Signature` header to the handler; verify the raw requestbody with `PRIMITIVE_WEBHOOK_SECRET` before trusting the parsed event.The `event` field is `email.received` for normal inbound mail, or amachine-mail type (`email.bounced`, `email.tls_report`,`email.dmarc_report`, `email.dmarc_failure`) for bounces and reports;the payload shape is otherwise identical. Code runs onPrimitive's edge runtime; there is no infrastructure to manage.Secrets land in `env` as encrypted bindings and are refreshed onevery redeploy.

Primitive Functions API is one of 22 APIs that Primitive publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Functions. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 20 operations across 12 paths, and defines 3 schemas. It is described by OpenAPI 3.2.0, at version 1.0.0.

Requests are made against a single base URL, https://api.primitive.dev/v1.

20 operations 12 paths 3 schemas 4 DELETE8 GET4 POST4 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0.0
Server
https://api.primitive.dev/v1
Authentication
HTTP Bearer, API Key
Contact
Resource Areas
1

Authentication & Security 2

Primitive Functions API declares 2 security schemes for authenticating requests. It accepts HTTP bearer tokens (BearerAuth). An API key is passed in the query as token (DownloadToken).

  • BearerAuth — API key with prim prefix or OAuth access token with primoat prefix: Authorization: Bearer . Access is governed by the caller's organization role (owner, admin,…
  • DownloadToken — Signed download token provided in webhook payloads

Paths & Operations 20

Across 12 paths, the API surfaces 20 operations — 4 DELETE, 8 GET, 4 POST, 4 PUT. Each is listed below with its method, path, parameters, and response codes.

Functions 20

Deploy JavaScript handlers that run on inbound mail. Each function is a single ESM module whose default export is an object with an async fetch(request, env) method, in the shape…

GET
/functions
List functions
listFunctions → 200401
POST
/functions
Deploy a function
createFunction 1 param body → 201400401409424429503
GET
/functions/{id}
Get a function
getFunction 1 param → 200401404
PUT
/functions/{id}
Update and redeploy a function
updateFunction 1 param body → 200400401404424429503
DELETE
/functions/{id}
Delete a function
deleteFunction 1 param → 200401404502
POST
/functions/{id}/test
Send a test invocation
testFunction 2 params body → 200400401404422502503
GET
/functions/{id}/test-runs/{run_id}/trace
Get a function test run trace
getFunctionTestRunTrace 2 params → 200400401403404
GET
/functions/routing-topology
Get the org's function routing topology
getOrgRoutingTopology → 200401403
GET
/functions/{id}/routing
Get a function's current route binding
getFunctionRouting 1 param → 200401404
PUT
/functions/{id}/route
Bind a route to a function
setFunctionRoute 1 param body → 200400401404
DELETE
/functions/{id}/route
Unbind any route from a function
unsetFunctionRoute 1 param → 200401404
GET
/functions/{id}/secrets
List a function's secrets
listFunctionSecrets 1 param → 200401404
POST
/functions/{id}/secrets
Create or update a secret
createFunctionSecret 2 params body → 200201400401404
PUT
/functions/{id}/secrets/{key}
Set a secret by key
setFunctionSecret 2 params body → 200201400401404
DELETE
/functions/{id}/secrets/{key}
Delete a secret
deleteFunctionSecret 2 params → 204400401404
GET
/org/secrets
List org-level (global) secrets
listOrgSecrets → 200401
POST
/org/secrets
Create or update an org secret
createOrgSecret 1 param body → 200201400401
PUT
/org/secrets/{key}
Set an org secret by key
setOrgSecret 1 param body → 200201400401
DELETE
/org/secrets/{key}
Delete an org secret
deleteOrgSecret 1 param → 204400401404
GET
/functions/{id}/logs
List a function's execution logs
listFunctionLogs 3 params → 200400401403404

Schemas 3

The contract defines 3 schemas that model the data the API accepts and returns. The most detailed are GateDenial (6 properties), ErrorResponse (2 properties), GateFix (2 properties). Each schema is shown below with its type and property counts.

GateFix
object
2 properties 2 required
ErrorResponse
object
2 properties 2 required
GateDenial
object
6 properties 4 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

primitive-functions-api-openapi.yml Raw ↑

Other APIs Primitive publishes across the network.

Primitive Account API
Primitive Agent API
Primitive CLI API
Primitive Demo API
Primitive Discovery API
Primitive Domains API
Primitive Emails API
Primitive Endpoints API
Primitive Filters API
Primitive Inbox API
Primitive Memories API
Primitive Payments API
Where this information came from

This is an independent, third-party profile of Primitive Functions API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.