AI Power Ups
Contents

Dev · PyPI JSON API

pypi.details

Official PyPI JSON metadata for the latest or an exact published version. No provider key needed. The summary includes Python requirements, dependencies, license and known vulnerabilities when supplied. details returns cached info with the full description, project links, distribution files and hashes. Deprecated downloads and releases fields are omitted; use pypi.versions and pypi.downloads instead.
Operation
POST /v1/capabilities/pypi.details/execute
operationId
executePypiDetails
Typical credits
0
Search deadline
15 s server-side
Paging
single result
Availability
Not checked
Cost basis: Free public PyPI API; cached details cost 0 credits. Availability is reported per deployment by GET /v1/catalog (available). The timestamped snapshot describes configuration, not provider uptime or your account's enabled choices. Check the catalog with your own key before a call. Credits are explained under credits and limits.

Request

Body of POST /v1/capabilities/pypi.details/execute, JSON, validated against the PypiDetailsRequest component of the public OpenAPI document. Defaults are applied server-side, so an omitted optional field behaves exactly as its default.

Request fields of pypi.details
FieldTypeRequiredDefaultConstraints and description
packagestringyesmin length 1, max length 214, pattern ^[A-Za-z0-9](?:[A-Za-z0-9._-]*[A-Za-z0-9])?$
PyPI project name. Case and runs of hyphens, underscores and dots are normalized.
versionstringnomin length 1, max length 128, pattern ^[A-Za-z0-9][A-Za-z0-9.!+_-]*$
Exact published version, e.g. 2.32.3. Omit for the latest version.
  • Unknown keys are rejected with 400 invalid_request.

Examples

Latest requests metadata

curl
curl -s -X POST https://ai-powerups.smalltree.cloud/v1/capabilities/pypi.details/execute \
  -H "Authorization: Bearer $AIPA_API_KEY" -H "Content-Type: application/json" \
  -d '{"package":"requests"}'

Exact version

curl
curl -s -X POST https://ai-powerups.smalltree.cloud/v1/capabilities/pypi.details/execute \
  -H "Authorization: Bearer $AIPA_API_KEY" -H "Content-Type: application/json" \
  -d '{"package":"requests","version":"2.32.3"}'
No recorded response is published for this capability yet. The envelope is the ExecuteResponse component (see sessions and records); the record keys below are what the adapter emits. A first call with the example above returns search_id, the records and the charge.

Result record

Every item in results[] carries record_id and title (contract, always present) and usually url and snippet. The keys below are the documented tier: produced deterministically by this capability, omitted when the source has no value, checked against recorded source fixtures in our test suite, and published as the PypiDetailsRecord component (all optional, extra keys allowed) so generated clients type them. The wire schema itself still validates only the base keys. See stability tiers.

Record keys of pypi.details
KeyTypePresenceNote
packagestringalways
versionstringalways
requires_pythonstringwhen the source has it
requires_diststring[]when the source has it
licensestringwhen the source has it
license_expressionstringwhen the source has it
project_urlsobjectwhen the source has it
vulnerabilitiesobject[]when the source has it
file_countintegeralways

Caveats

  • Metadata is publisher-supplied. Deprecated downloads counters and releases are omitted. Responses have an 8 MiB limit.

Follow-ups

  • Paging: Single result; more is refused with 400 invalid_request.
  • Update: not offered.
  • Record actions:
    • details: Cached metadata with README, distribution URLs and hashes, and known vulnerabilities.
  • Detail behaviour: Stored at search time; details is free and never calls the provider. Free cached metadata from official PyPI.
record action
curl -s -X POST https://ai-powerups.smalltree.cloud/v1/follow-up \
  -H "Authorization: Bearer $AIPA_API_KEY" -H "Content-Type: application/json" \
  -d '{"record_id":"rec_…","action":"details"}'

Record detail objects of this capability are provider-shaped: documented by observation, not by schema. Full follow-up semantics: follow-up.

Typed client

With types generated from the public document (see types, client and samples) the call is path-keyed and the body is checked at compile time:

TypeScript (openapi-fetch)
const { data, error } = await client.POST("/v1/capabilities/pypi.details/execute", {
  body: {
    "package": "requests"
  },
});
if (error) throw new Error(`${error.error.code}: ${error.error.message}`);
for (const record of data.results) console.log(record.record_id, record.title);