Skip to content
Docs menu

robots

Robot-kind repo extras — robot card

11 operations · 37 schemas

GET /v1/robots/{owner}/{repo}/card

Get a robot card

getRobotCard · scope none

The structured robot description (DOF, actuators, mass, limits, MJCF pointer) of a robot-kind repo. 404 until a card is set; 409 problem if the repo kind is not robot.

Parameters

getRobotCard parameters
NameInTypeDescription
ownerrequiredpathHandle

Repo owner handle (username or org slug).

reporequiredpathSlug

Repo slug.

Responses

getRobotCard responses
StatusDescriptionBody
200

The robot card.

RobotCard
404

Resource not found (or hidden from the caller).

Problemapplication/problem+json
409

State conflict (duplicate handle/slug, wrong repo kind, terminal job, ...).

Problemapplication/problem+json

PUT /v1/robots/{owner}/{repo}/card

Set a robot card

putRobotCard · scope key:write

Full replace of the robot card on a robot-kind repo. mjcf_path is the repo-relative path of the MJCF file (upload it via the files endpoints first). 409 problem if the repo kind is not robot. Since M17a the hub checks what it stores: a mjcf_path that is not a file of this repo, an MJCF that does not parse, referenced assets or includes missing from the repo, interface.joint_order names that are not 1-DoF joints of the MJCF, and an interface.base that contradicts the model's free joint are each a 422 whose errors[] carry the same code (as type) that validateRobot reports — rejected with the reason, never repaired.

Parameters

putRobotCard parameters
NameInTypeDescription
ownerrequiredpathHandle

Repo owner handle (username or org slug).

reporequiredpathSlug

Repo slug.

Request body

application/json · required · RobotCardPut

putRobotCard request body
FieldTypeDescription
dofrequiredinteger

≥ 0

actuatorsrequiredarray of Actuator
mass_kgnumber | null

> 0

limitsmap of JointLimits | null
mjcf_pathFilePath | null
description_mdstring | null

length ≤ 65536

interfaceEmbodimentInterface | null

Omit or null to store a card without one. When limits is given, every joint_order name must be one of its keys (422 otherwise).

validationRobotValidationRecord | null

UI2: the report lucen robot validate produced for exactly these files, stored verbatim beside the card. Omit or null to store none. The hub does not verify a mujoco record; it is shown as the publisher's report, dated.

thumbnail_pathsRobotThumbnailPaths | null

UIV2-thumbs: both paths must already be files of this repo, with a .png, .jpg, .jpeg or .webp suffix (card.thumbnails, 422 otherwise); the hub never opens them. PUT is a full replace, so a card sent without it clears it. lucen robot publish renders thumbnail.png / thumbnail-dark.png and sends them.

Responses

putRobotCard responses
StatusDescriptionBody
200

Stored robot card.

RobotCard
401

Missing or invalid credentials.

Problemapplication/problem+json
403

Authenticated but not allowed (visibility, membership or scope).

Problemapplication/problem+json
404

Resource not found (or hidden from the caller).

Problemapplication/problem+json
409

State conflict (duplicate handle/slug, wrong repo kind, terminal job, ...).

Problemapplication/problem+json
422

Request failed validation.

Problemapplication/problem+json

POST /v1/robots/{owner}/{repo}/validate

Validate a robot card against the repo's MJCF, without writing

validateRobot · scope key:read

The report an agent iterates against before putRobotCard: is mjcf_path a file of this repo, does it parse, is every asset it references (and every <include>) in the repo, is every interface.joint_order name a 1-DoF joint of the model, does interface.base agree with the presence of a free joint. card is the candidate (the body of a putRobotCard you have not sent yet); omit it, or send null, to validate the stored card. Nothing is written, and the answer is 200 whether or not the card is good — ok and each check's status say which. A candidate the RobotCardPut schema itself refuses comes back as card.schema failures in the same report rather than as a 422. The checks are static (hardened XML parsing only; the server never runs MuJoCo): lucen robot validate adds the dynamic ones on the user's machine and reports in the same shape. Every fail here is a 422 from putRobotCard, with the same code as the error's type. A repo the caller cannot see is 404, never 403; 409 if the repo kind is not robot; 404 when card is omitted and no card is stored.

Parameters

validateRobot parameters
NameInTypeDescription
ownerrequiredpathHandle

Repo owner handle (username or org slug).

reporequiredpathSlug

Repo slug.

Request body

application/json · RobotValidateRequest

validateRobot request body
FieldTypeDescription
cardRobotCardPut | null

Responses

validateRobot responses
StatusDescriptionBody
200

The validation report (for a good card and a bad one alike).

RobotValidationReport
401

Missing or invalid credentials.

Problemapplication/problem+json
403

Authenticated but not allowed (visibility, membership or scope).

Problemapplication/problem+json
404

Resource not found (or hidden from the caller).

Problemapplication/problem+json
409

State conflict (duplicate handle/slug, wrong repo kind, terminal job, ...).

Problemapplication/problem+json
422

Request failed validation.

Problemapplication/problem+json
503

A service this endpoint needs is not configured in this deployment (M0's boot guarantee: the API boots with zero secrets, and an endpoint that needs one says so instead of returning a stack trace).

Problemapplication/problem+json

GET /v1/robot-checks

List hosted robot checks

listRobotChecks · scope key:read

Checks the caller can see — ones they created, or on a robot repo they can write — newest first. A lucen robot worker polls this with status=queued&executor=worker. No check is public. (R1)

Parameters

listRobotChecks parameters
NameInTypeDescription
robot_repoquerystring

length ≤ 130

owner/slug of the robot repo.

statusqueryJobStatus
executorqueryRobotCheckJobExecutor
limitqueryinteger

default 20 · ≥ 1 · ≤ 100

Page size.

cursorquerystring

length ≤ 512

Opaque cursor from the previous page's next_cursor.

Responses

listRobotChecks responses
StatusDescriptionBody
200

A page of checks.

RobotCheckJobPage
401

Missing or invalid credentials.

Problemapplication/problem+json
422

Request failed validation.

Problemapplication/problem+json

POST /v1/robot-checks

Queue a hosted check of a robot repo's model

createRobotCheck · scope key:write

The hub never runs MuJoCo, so a robot someone dropped into the browser is checked by a job: it pulls the repo, runs the CLI's own lucen robot init on entry with exactly the answers given here (no defaults are filled in: control_hz and action always, base for a URDF), then lucen robot validate, and uploads the draft card, the converted MJCF when entry is a URDF, and the report. Nothing is written to the repo until a person calls publishRobotCheck.

The repo must be a robot repo the caller can write (an invisible one is 404, a visible one you cannot write 403, the wrong kind 409), and entry must be one of its files (422). The file list is snapshotted now (path, sha256, size): the job checks exactly those bytes, and publishing refuses once any of them changed. executor omitted means the hub's hosted executor (modal) when this deployment has one, else worker — a lucen robot worker the owner runs; modal on a deployment without it is 503 and nothing is recorded. A check is unpriced CPU (priced: false), and each account (L0: a user, across all their keys and sessions) may create ROBOT_CHECK_DAILY_QUOTA of them a day (429 with Retry-After and X-Robot-Check-Quota-*). (R1)

Hosted execution (L0, K2). The hosted executor runs for owners in the deployment's HOSTED_OWNERS (default lucen; * = everyone) and, for every other account, inside its monthly hosted allowance (HOSTED_ALLOWANCE_USD, HardwareTierList.hosting.allowance): an omitted executor means modal while the check's reservation fits the allowance, else worker; an explicit modal that does not fit is 403 (forbidden.hosted_allowance, naming what is left and when it resets), and with the allowance at 0 it is L0's 403 (forbidden.hosted_owner). A hosted check is billed at the robot_check function's CPU host from claim to finish (cost_usd, one ledger row).

A model check (K2, kind: model). The same job, for a policy: model.repo is a model repo the caller can write (the private draft), robot_repo the robot it is checked against (read access; omitted, the job only READS the policy — its stamp, graph widths, an import's revision, size and parameter count — so a robot can be suggested from the stamp, listRepos?interface_fingerprint=, before anything is checked or copied), and entry either an ONNX in the draft or a checkpoint directory (lucen_manifest.json + policy/, or a LeRobot config.json + model.safetensors) — or, instead of entry, model.hf_repo (org/name[@revision]): the job fetches that public LeRobot policy from Hugging Face over HTTPS (size-capped, revision and licence recorded). The job reads the policy's stamped contract and checks it against the robot's interface (intake.embodiment: match, mismatch with the differing fields, unstamped); for an unstamped policy it derives the contract from the interface — the one lucen model stamp implementation — asking only for what the robot cannot know (model.obs and model.control_class; a blocking needs_you when missing). The report's codes: manifest.stamped, onnx.shapes, contract.joint_order, contract.action, contract.observation, contract.rate, embodiment.fingerprint (plus source.hf for an import), each with a one-sentence message and data.verdict (match, mismatch, stamped, derived). Publish (publishRobotCheck) links the (stamped) files into the draft — or into repo, created for the caller — sets the model's meta (robot, control class, embodiment fingerprint) and, with smoke, queues the smoke sim gate as the publisher.

Request body

application/json · required · RobotCheckJobCreate

createRobotCheck request body
FieldTypeDescription
kindRobotCheckKind
robot_repostring

length ≤ 130 · pattern ^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?/[a-z0-9](?:[a-z0-9-]*[a-z0-9])?$

owner/slug of a robot repo the caller can write (required for a robot check) — or, for a model check, can read: the robot the policy is checked against; omitted, a model check only reads.

modelModelCheckRequest | null

Required for kind: model, refused otherwise.

entryFilePath | null

A robot check: the model file (required). A model check: the ONNX or checkpoint directory in model.repo (required unless model.hf_repo).

basestring | null

Required when entry is a URDF (.urdf): a URDF cannot say whether the base is bolted down. For an MJCF it is read from the model and this only asserts it.

control_hznumber | null

> 0 · ≤ 2000

The rate policies run at on the REAL robot (--control-hz). No model file says it. Required for a robot check.

actionRobotCheckJobAction | null

Required for a robot check.

optionsRobotCheckJobOptions | null
executorRobotCheckJobExecutor | null

Null or absent — modal when this deployment has it and the hub may host the owner (HOSTED_OWNERS, or the hosted allowance), else worker.

dropRobotCheckJobDrop | null

Responses

createRobotCheck responses
StatusDescriptionBody
201

Check queued.

RobotCheckJob
401

Missing or invalid credentials.

Problemapplication/problem+json
403

Authenticated but not allowed (visibility, membership or scope).

Problemapplication/problem+json
404

Resource not found (or hidden from the caller).

Problemapplication/problem+json
409

State conflict (duplicate handle/slug, wrong repo kind, terminal job, ...).

Problemapplication/problem+json
422

Request failed validation.

Problemapplication/problem+json
429

This account's daily check quota is spent.

Problemapplication/problem+json
503

A service this endpoint needs is not configured in this deployment (M0's boot guarantee: the API boots with zero secrets, and an endpoint that needs one says so instead of returning a stack trace).

Problemapplication/problem+json

GET /v1/robot-checks/{check_id}

Get a hosted robot check

getRobotCheck · scope key:read

Status, the tail of the job's log, and once it finished: the report (engine: mujoco, the CLI's shape and codes), the draft (the model's facts, needs_you with severities, the card the hub read back from the uploaded robot_card.json), the artifacts with presigned 1-hour downloads, and whether it can be published (publish_blockers). Visible to its creator and to anyone who can write the robot repo; anything else is 404. (R1)

Parameters

getRobotCheck parameters
NameInTypeDescription
check_idrequiredpathId

Hosted robot check id (rchk_...).

Responses

getRobotCheck responses
StatusDescriptionBody
200

The check.

RobotCheckJob
401

Missing or invalid credentials.

Problemapplication/problem+json
404

Resource not found (or hidden from the caller).

Problemapplication/problem+json

POST /v1/robot-checks/{check_id}/claim

Claim a queued check (robot check worker protocol)

claimRobotCheck · scope key:write

Compare-and-set queued → running, exactly like claimRollout: one caller wins, everyone else gets 409 naming the holder. Records the claiming credential — presignRobotCheckArtifacts and reportRobotCheck are 409 from any other. The response is the check with sources: the snapshot's files with presigned 1-hour GETs of exactly the bytes that were snapshotted, so the job needs no access to the repo at all — it never reads it through the repo's routes and can never write to it. No lease: a dead worker leaves the check running until someone cancels it. (R1)

Parameters

claimRobotCheck parameters
NameInTypeDescription
check_idrequiredpathId

Hosted robot check id (rchk_...).

Request body

application/json · required · RobotCheckJobClaim

claimRobotCheck request body
FieldTypeDescription
workerrequiredstring

length 1–128

A name for the worker, recorded as claimed_by.

Responses

claimRobotCheck responses
StatusDescriptionBody
200

Claimed; the check with its sources.

RobotCheckJob
401

Missing or invalid credentials.

Problemapplication/problem+json
403

Authenticated but not allowed (visibility, membership or scope).

Problemapplication/problem+json
404

Resource not found (or hidden from the caller).

Problemapplication/problem+json
409

State conflict (duplicate handle/slug, wrong repo kind, terminal job, ...).

Problemapplication/problem+json
422

Request failed validation.

Problemapplication/problem+json

POST /v1/robot-checks/{check_id}/artifacts

Presign uploads for a running check's artifacts

presignRobotCheckArtifacts · scope key:write

One presigned PUT per artifact under robot-checks/{check_id}/files/ (outside the content-addressed blobs/ prefix). name is the repo path the artifact would take if the check is published, and only four kinds are accepted: robot_card.json, the MJCF converted from a URDF entry (the entry with an .xml suffix), meshes under meshes/, and the two stills thumbnail.png / thumbnail-dark.png (UIV2-thumbs; publish sets thumbnail_paths only when both were reported). Only a running check may presign, and only the credential that claimed it (409 otherwise); URLs live 1 h. (R1)

Parameters

presignRobotCheckArtifacts parameters
NameInTypeDescription
check_idrequiredpathId

Hosted robot check id (rchk_...).

Request body

application/json · required · RobotCheckJobArtifactsRequest

presignRobotCheckArtifacts request body
FieldTypeDescription
filesrequiredarray of RobotCheckJobArtifactRequest

items 1–100

Responses

presignRobotCheckArtifacts responses
StatusDescriptionBody
200

One presigned PUT per requested artifact.

RobotCheckJobArtifactsResponse
401

Missing or invalid credentials.

Problemapplication/problem+json
403

Authenticated but not allowed (visibility, membership or scope).

Problemapplication/problem+json
404

Resource not found (or hidden from the caller).

Problemapplication/problem+json
409

State conflict (duplicate handle/slug, wrong repo kind, terminal job, ...).

Problemapplication/problem+json
422

Request failed validation.

Problemapplication/problem+json

POST /v1/robot-checks/{check_id}/report

Report progress or the result of a claimed check

reportRobotCheck · scope key:write

The worker's one write path after claimRobotCheck: the check must be running and the caller the credential that claimed it (409 otherwise). log_chunk (≤ 256 KiB) is stored under robot-checks/{id}/logs/ and appended to the row's log tail. The terminal succeeded report carries the report (the CLI's, engine: mujoco), the draft summary and the artifacts it uploaded; the hub then hashes every artifact itself and reads robot_card.json back (≤ 1 MiB, a JSON object), so what a person later publishes is pinned to the bytes that were checked. succeeded means the job produced a verdict — a model that fails to compile is a succeeded check whose report fails; failed means the job itself broke. A named artifact that was never uploaded, or is not one of the three accepted kinds, is 422. (R1)

Parameters

reportRobotCheck parameters
NameInTypeDescription
check_idrequiredpathId

Hosted robot check id (rchk_...).

Request body

application/json · required · RobotCheckJobReport

reportRobotCheck request body
FieldTypeDescription
statusRobotCheckJobReportStatus | null
log_chunkstring | null

length ≤ 262144

Output since the last report, ≤ 256 KiB of UTF-8.

errorstring | null

length ≤ 4000

Why the job broke; expected with status: failed.

reportRobotValidationReport | null

The verdict, engine: mujoco — required with status: succeeded.

draftRobotCheckJobDraftIn | null
artifactsarray of RobotCheckJobArtifactRef

items ≤ 256

The artifacts uploaded through presignRobotCheckArtifacts, by name.

engineobject | null

mujoco version, the worker's name.

intakeModelIntake | null

A model check's findings (K2) — required with status: succeeded for kind: model.

Responses

reportRobotCheck responses
StatusDescriptionBody
200

Recorded; the check as it now stands.

RobotCheckJob
401

Missing or invalid credentials.

Problemapplication/problem+json
403

Authenticated but not allowed (visibility, membership or scope).

Problemapplication/problem+json
404

Resource not found (or hidden from the caller).

Problemapplication/problem+json
409

State conflict (duplicate handle/slug, wrong repo kind, terminal job, ...).

Problemapplication/problem+json
413

A log chunk is over its size limit.

Problemapplication/problem+json
422

Request failed validation.

Problemapplication/problem+json

POST /v1/robot-checks/{check_id}/publish

Publish a check's draft card into the robot repo, as the caller

publishRobotCheck · scope key:write

What only a person (or a key acting for them) does, never the job: link the check's artifacts into the robot repo and store the drafted card with the job's report as its validation record, under the caller's principal — write on the robot repo is required (403 otherwise; 404 if the check or the repo is invisible), and the key that claimed the check is 403 even with write: a worker proposes, a person publishes. The hub copies each artifact into content-addressed storage and hashes the copy; a digest that differs from the one it recorded at the terminal report is 409, so the bytes linked are the bytes that were checked. The card then goes through putRobotCard's own static checks and is refused with their reasons (422, nothing linked). 409 also when the check is not succeeded, was already published, its report failed, its draft lists a blocking needs_you item, or a snapshotted file of the repo changed since the check was queued — any edit means a new check. visibility in the body is applied to the repo last (the drop creates it private), audited as a repo.update. (R1)

Parameters

publishRobotCheck parameters
NameInTypeDescription
check_idrequiredpathId

Hosted robot check id (rchk_...).

Request body

application/json · RobotCheckJobPublish

publishRobotCheck request body
FieldTypeDescription
visibilityVisibility | null
repostring | null

length ≤ 130 · pattern ^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?/[a-z0-9](?:[a-z0-9-]*[a-z0-9])?$

A model check only (K2): publish into this model repo instead of the draft — created for the caller when it does not exist (the caller must be able to create under that owner), 409 when it exists and holds files. The draft is left as it was.

smokeboolean

default false

A model check only (K2): after publishing, queue the smoke sim gate of the model on the checked robot, as the caller — CPU, under every rollout rule and the hosted allowance.

Responses

publishRobotCheck responses
StatusDescriptionBody
200

Published; the check with published filled in.

RobotCheckJob
401

Missing or invalid credentials.

Problemapplication/problem+json
403

Authenticated but not allowed (visibility, membership or scope).

Problemapplication/problem+json
404

Resource not found (or hidden from the caller).

Problemapplication/problem+json
409

State conflict (duplicate handle/slug, wrong repo kind, terminal job, ...).

Problemapplication/problem+json
422

Request failed validation.

Problemapplication/problem+json
503

A service this endpoint needs is not configured in this deployment (M0's boot guarantee: the API boots with zero secrets, and an endpoint that needs one says so instead of returning a stack trace).

Problemapplication/problem+json

POST /v1/robot-checks/{check_id}/cancel

Cancel a hosted robot check

cancelRobotCheck · scope key:write

A queued or running check becomes canceled in this request; a modal check's call is terminated first (502 if Modal refuses, and nothing changes). A worker check's worker learns on its next report (409). A terminal check is 409. (R1)

Parameters

cancelRobotCheck parameters
NameInTypeDescription
check_idrequiredpathId

Hosted robot check id (rchk_...).

Responses

cancelRobotCheck responses
StatusDescriptionBody
202

Canceled; the check as it now stands.

RobotCheckJob
401

Missing or invalid credentials.

Problemapplication/problem+json
403

Authenticated but not allowed (visibility, membership or scope).

Problemapplication/problem+json
404

Resource not found (or hidden from the caller).

Problemapplication/problem+json
409

State conflict (duplicate handle/slug, wrong repo kind, terminal job, ...).

Problemapplication/problem+json
502

Modal refused to terminate the call; nothing changed.

Problemapplication/problem+json

Schemas (37)

The schemas these operations reach before any other tag’s do. A type that links elsewhere is rendered on that tag’s page.

RobotCardPut

object

RobotCardPut fields
FieldTypeDescription
dofrequiredinteger

≥ 0

actuatorsrequiredarray of Actuator
mass_kgnumber | null

> 0

limitsmap of JointLimits | null
mjcf_pathFilePath | null
description_mdstring | null

length ≤ 65536

interfaceEmbodimentInterface | null

Omit or null to store a card without one. When limits is given, every joint_order name must be one of its keys (422 otherwise).

validationRobotValidationRecord | null

UI2: the report lucen robot validate produced for exactly these files, stored verbatim beside the card. Omit or null to store none. The hub does not verify a mujoco record; it is shown as the publisher's report, dated.

thumbnail_pathsRobotThumbnailPaths | null

UIV2-thumbs: both paths must already be files of this repo, with a .png, .jpg, .jpeg or .webp suffix (card.thumbnails, 422 otherwise); the hub never opens them. PUT is a full replace, so a card sent without it clears it. lucen robot publish renders thumbnail.png / thumbnail-dark.png and sends them.

RobotValidateRequest

object

What to validate. card is a candidate RobotCardPut; null or absent means the card already stored on the repo.

RobotValidateRequest fields
FieldTypeDescription
cardRobotCardPut | null

RobotValidationReport

object

RobotValidationReport fields
FieldTypeDescription
okrequiredboolean

True when no check failed.

graderequiredstring

one of pass · warn · fail

The worst status among the checks that ran.

sourcerequiredstring

one of candidate · stored

enginerequiredstring

one of static · mujoco

static from the hub (XML only); mujoco from lucen robot validate, which compiles the model and adds the dynamic checks.

mjcf_pathstring | null
interface_fingerprintstring | null

pattern ^[0-9a-f]{64}$

What the card's interface hashes to (null without one, or if it is invalid).

modelRobotModelSummary | null
checksrequiredarray of RobotValidationCheck

items ≤ 128

JobStatus

string

one of queued · running · succeeded · failed · canceled

Job lifecycle: queued → running → one of succeeded | failed | canceled (terminal).

RobotCheckJobExecutor

string

one of worker · modal

Where a hosted robot check runs (R1). worker — it waits queued for a lucen robot worker the owner runs. modal — on a deployment that names a deployed Modal app (MODAL_APP_NAME), the hub spawns the app's robot_check function (the CPU rollout image) after the commit; the container claims and reports like any worker, with a key minted for the check (K2). modal is billed at the function's CPU host from claim to finish; worker is unpriced.

RobotCheckJobPage

object

RobotCheckJobPage fields
FieldTypeDescription
itemsrequiredarray of RobotCheckJob
next_cursorrequiredstring | null

RobotCheckJobCreate

object

RobotCheckJobCreate fields
FieldTypeDescription
kindRobotCheckKind
robot_repostring

length ≤ 130 · pattern ^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?/[a-z0-9](?:[a-z0-9-]*[a-z0-9])?$

owner/slug of a robot repo the caller can write (required for a robot check) — or, for a model check, can read: the robot the policy is checked against; omitted, a model check only reads.

modelModelCheckRequest | null

Required for kind: model, refused otherwise.

entryFilePath | null

A robot check: the model file (required). A model check: the ONNX or checkpoint directory in model.repo (required unless model.hf_repo).

basestring | null

Required when entry is a URDF (.urdf): a URDF cannot say whether the base is bolted down. For an MJCF it is read from the model and this only asserts it.

control_hznumber | null

> 0 · ≤ 2000

The rate policies run at on the REAL robot (--control-hz). No model file says it. Required for a robot check.

actionRobotCheckJobAction | null

Required for a robot check.

optionsRobotCheckJobOptions | null
executorRobotCheckJobExecutor | null

Null or absent — modal when this deployment has it and the hub may host the owner (HOSTED_OWNERS, or the hosted allowance), else worker.

dropRobotCheckJobDrop | null

RobotCheckJob

object

RobotCheckJob fields
FieldTypeDescription
idrequiredId
kindrequiredRobotCheckKind
statusrequiredJobStatus
robot_reporequiredRepoRef | null

The robot — null for a model check that only reads (K2).

model_repoRepoRef | null

A model check's draft repo (K2); publishing writes there unless repo names another.

modelModelCheckRequest | null

A model check's request, as given.

intakeModelIntake | null
entryrequiredFilePath
basestring | null
control_hzrequirednumber | null

Null for a model check.

actionrequiredRobotCheckJobAction | null

Null for a model check.

optionsRobotCheckJobOptions | null
executorrequiredRobotCheckJobExecutor
created_byUserPublic | null
created_atrequiredstring (date-time)
started_atstring (date-time) | null (date-time)
finished_atstring (date-time) | null (date-time)
claimed_bystring | null
claimed_atstring (date-time) | null (date-time)
heartbeat_atstring (date-time) | null (date-time)
modal_call_idstring | null
dispatched_atstring (date-time) | null (date-time)
errorstring | null
sources_countinteger

Files in the snapshot.

sources_bytesinteger

Their total size.

dropRobotCheckJobDrop | null
sourcesarray of RobotCheckJobSource | null

The snapshot, with presigned GETs — on the claim response only.

log_tailstring | null

The last ≤ 64 KiB of the job's log.

reportRobotValidationReport | null
draftRobotCheckJobDraft | null
engineobject | null
artifactsrequiredarray of RobotCheckJobArtifactOut
publish_blockersrequiredarray of string

Why Publish would be refused right now, one sentence each; empty means it would go through (the hub's static checks still run).

publishedRobotCheckJobPublished | null
pricedrequiredboolean

True for a modal check (billed at the robot_check function's CPU host, claim to finish); false for a worker check.

cost_usdnumber | null

What a finished modal check cost; null until it finishes, and for worker.

RobotCheckJobClaim

object

RobotCheckJobClaim fields
FieldTypeDescription
workerrequiredstring

length 1–128

A name for the worker, recorded as claimed_by.

RobotCheckJobArtifactsRequest

object

RobotCheckJobArtifactsRequest fields
FieldTypeDescription
filesrequiredarray of RobotCheckJobArtifactRequest

items 1–100

RobotCheckJobArtifactsResponse

object

RobotCheckJobArtifactsResponse fields
FieldTypeDescription
uploadsrequiredarray of RobotCheckJobArtifactUpload

RobotCheckJobReport

object

One progress or terminal report from a robot check worker. Every field is optional.

RobotCheckJobReport fields
FieldTypeDescription
statusRobotCheckJobReportStatus | null
log_chunkstring | null

length ≤ 262144

Output since the last report, ≤ 256 KiB of UTF-8.

errorstring | null

length ≤ 4000

Why the job broke; expected with status: failed.

reportRobotValidationReport | null

The verdict, engine: mujoco — required with status: succeeded.

draftRobotCheckJobDraftIn | null
artifactsarray of RobotCheckJobArtifactRef

items ≤ 256

The artifacts uploaded through presignRobotCheckArtifacts, by name.

engineobject | null

mujoco version, the worker's name.

intakeModelIntake | null

A model check's findings (K2) — required with status: succeeded for kind: model.

RobotCheckJobPublish

object

How to publish. visibility is applied to the repo in the same request (the drop creates it private); null or absent keeps it as it is.

RobotCheckJobPublish fields
FieldTypeDescription
visibilityVisibility | null
repostring | null

length ≤ 130 · pattern ^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?/[a-z0-9](?:[a-z0-9-]*[a-z0-9])?$

A model check only (K2): publish into this model repo instead of the draft — created for the caller when it does not exist (the caller must be able to create under that owner), 409 when it exists and holds files. The draft is left as it was.

smokeboolean

default false

A model check only (K2): after publishing, queue the smoke sim gate of the model on the checked robot, as the caller — CPU, under every rollout rule and the hosted allowance.

RobotModelSummary

object

What the validator read out of the MJCF (null fields when it could not).

RobotModelSummary fields
FieldTypeDescription
modelstring | null

length ≤ 256

basestring | null
jointsarray of string

items ≤ 1024

Named 1-DoF (hinge / slide) joints, in document order.

filesarray of string

items ≤ 4096

Repo paths the model needs — the MJCF, its includes and its assets.

keyframesarray of string

items ≤ 256

RobotCheckKind

string

one of robot · model

What a check is about (K2). robot — a robot repo's model (R1); model — a policy in a model repo, checked against a robot.

ModelCheckRequest

object

The model-check half of a check (K2, kind: model).

ModelCheckRequest fields
FieldTypeDescription
reporequiredstring

length ≤ 130 · pattern ^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?/[a-z0-9](?:[a-z0-9-]*[a-z0-9])?$

owner/slug of the model repo (the draft) the caller can write.

hf_repostring | null

pattern ^[A-Za-z0-9][A-Za-z0-9._-]{0,95}/[A-Za-z0-9][A-Za-z0-9._-]{0,95}(@[A-Za-z0-9._/-]{1,128})?$

Import instead of upload: a public Hugging Face LeRobot policy (config.json + model.safetensors), org/name[@revision].

control_classControlClass | null

For a policy whose manifest does not say: the layer to stamp (default reflex for an ONNX, skill for a LeRobot checkpoint).

obsModelCheckObs | null

RobotCheckJobAction

string

one of position_offset · position_absolute · velocity · torque

What one action vector means — lucen robot init --action.

RobotCheckJobOptions

object

The optional lucen robot init flags, one field per flag; an absent or null field is a flag not passed. Nothing is defaulted here — init writes what it writes without the flag (a needs_you entry, or a value derived from the model).

RobotCheckJobOptions fields
FieldTypeDescription
action_scalenumber | null

> 0

--action-scale: action → joint units.

action_clipnumber | null

> 0

--action-clip.

kpnumber | null

≥ 0

--kp: PD stiffness for every joint.

kdnumber | null

≥ 0

--kd: PD damping for every joint.

armaturenumber | null

≥ 0

--armature: reflected rotor inertia (kg·m²) for every joint.

friction_lossnumber | null

≥ 0

--friction-loss: Coulomb friction (N·m) for every joint.

proprioceptionarray of string | null

items ≤ 32

--proprioception: what the REAL robot can observe, snake_case terms.

commandstring | null

--command: the command space.

default_posemap of number | null

--default-pose (P1): joint name → position (rad or m) of the pose policies start from — what the drop's "Default pose" field sends for a model with no keyframe, whose pose would otherwise be qpos0. A joint left out keeps the model's value; init refuses a name the model does not have, or a value outside the joint's range.

discard_visualboolean

default false

--discard-visual (URDF only): convert with collision geometry alone.

RobotCheckJobDrop

object

What the browser read out of the dropped zip and what its upload moved — the client's own account, stored with the check so the page can print it again. The hub never sees the zip and checks none of this; the snapshot (sources_count, sources_bytes) is the hub's own view.

RobotCheckJobDrop fields
FieldTypeDescription
filenamestring

length ≤ 255

zip_bytesinteger

≥ 0

filesinteger

≥ 0

Entries kept (after the refused ones).

unpacked_bytesinteger

≥ 0

entry_candidatesarray of FilePath

items ≤ 64

refusedarray of RobotCheckJobRefusedPath

items ≤ 64

uploaded_filesinteger

≥ 0

uploaded_bytesinteger

≥ 0

deduped_filesinteger

≥ 0

Files the hub already held (parts: []) — 0 bytes sent.

deduped_bytesinteger

≥ 0

RepoRef

object

Lightweight repo pointer used inside jobs.

RepoRef fields
FieldTypeDescription
idrequiredId
full_namerequiredstring

ModelIntake

object

What a model check found (K2): the policy, its contract against the robot, and — for an import — its source.

ModelIntake fields
FieldTypeDescription
policy_pathstring | null

The ONNX path or checkpoint directory publishing writes.

policy_formatstring | null

onnx, lerobot or lerobot-peft.

policy_typestring | null

onnx, or the LeRobot config's type (act, diffusion, …).

embodimentstring

one of match · mismatch · unstamped · unchecked

unchecked — no robot was named: the check only read the policy.

stamped_by_checkboolean

The policy was unstamped and this check derived its contract from the interface.

differingarray of ModelIntakeDifference

items ≤ 64

control_classControlClass | null
embodiment_fingerprintstring | null

The fingerprint the (stamped) manifest records.

robot_fingerprintstring | null

The robot's interface_fingerprint when checked.

summarystring | null

The contract in one line (joints, observation, action, rate, chunk).

manifestobject | null

The policy's manifest as read (or as the check derived it).

graphobject | null

An ONNX's graph widths, {input, output}.

paramsinteger | null

Parameter count, from the weights' safetensors header.

sourceModelIntakeSource | null

RobotCheckJobSource

object

One file of the repo as it was when the check was queued.

RobotCheckJobSource fields
FieldTypeDescription
pathrequiredFilePath
sha256requiredSha256
sizerequiredinteger

≥ 0

urlstring (uri) | null (uri)

Presigned 1-hour GET of exactly these bytes — on the claim response only.

RobotCheckJobDraft

object

The draft as the page shows it: the worker's summary of the model, and — read by the hub from the uploaded robot_card.json — the card that Publish would store and its needs_you.

RobotCheckJobDraft fields
FieldTypeDescription
sourcestring | null
mjcf_pathstring | null
modelobject | null
derivedarray of string
conversionobject | null
cardobject | null

robot_card.json without needs_you — exactly what Publish sends to putRobotCard.

needs_youarray of RobotCheckJobNeed
blockinginteger

How many needs_you entries are blocking; Publish is refused while > 0.

RobotCheckJobArtifactOut

object

RobotCheckJobArtifactOut fields
FieldTypeDescription
pathrequiredFilePath
sha256requiredSha256
sizerequiredinteger
replacesrequiredboolean

A file of the snapshot sits at this path; publishing replaces it.

urlstring (uri) | null (uri)

Presigned 1-hour GET.

RobotCheckJobPublished

object

RobotCheckJobPublished fields
FieldTypeDescription
atrequiredstring (date-time)
byUserPublic | null
interface_fingerprintstring | null

pattern ^[0-9a-f]{64}$

visibilityVisibility
filesrequiredarray of RobotCheckJobPublishedFile
smoke_rollout_idstring | null

The smoke gate a model check's publish queued (smoke: true).

smoke_errorstring | null

Why that gate could not be queued (the publish still stands).

RobotCheckJobArtifactRequest

object

RobotCheckJobArtifactRequest fields
FieldTypeDescription
namerequiredFilePath
sizerequiredinteger

≥ 0 · ≤ 268435456

Bytes (≤ 256 MiB; a single PUT).

content_typestring

one of application/json · application/xml · text/plain · application/octet-stream · image/png

default "application/octet-stream"

image/png is the stills' (UIV2-thumbs).

RobotCheckJobArtifactUpload

object

RobotCheckJobArtifactUpload fields
FieldTypeDescription
namerequiredstring
keyrequiredStorageKey
urlrequiredstring (uri)

Presigned PUT; send exactly size bytes with Content-Type as declared.

expires_atrequiredstring (date-time)

RobotCheckJobReportStatus

string

one of running · succeeded · failed

The only transitions a worker may make — running → succeeded | failed.

RobotCheckJobDraftIn

object

What lucen robot init said about the model, as the worker reports it.

RobotCheckJobDraftIn fields
FieldTypeDescription
sourcestring

one of mjcf · urdf

mjcf_pathstring | null

length ≤ 1024

modelobject | null

name, base, joints, actuators, mass_kg, physics_dt_s, default_pose_from.

derivedarray of string

items ≤ 256

conversionobject | null

For a URDF — the MJCF written, what the conversion dropped, meshes copied.

RobotCheckJobArtifactRef

object

RobotCheckJobArtifactRef fields
FieldTypeDescription
pathrequiredFilePath

ModelCheckObs

object

What only the person knows about an unstamped ONNX — the observation blocks it consumes, in order (lucen model stamp --obs). Everything robot-side is derived from the robot's interface.

ModelCheckObs fields
FieldTypeDescription
blocksrequiredarray of string

items 1–32

scalesobject | null
cycle_time_snumber | null

> 0

profilestring | null

length ≤ 128

taskobject | null

RobotCheckJobRefusedPath

object

RobotCheckJobRefusedPath fields
FieldTypeDescription
pathrequiredstring

length ≤ 1024

reasonrequiredstring

length ≤ 300

ModelIntakeDifference

object

ModelIntakeDifference fields
FieldTypeDescription
fieldrequiredstring

length ≤ 128

policyany

What the policy's contract says.

robotany

What the robot's interface derives.

ModelIntakeSource

object

Where an imported policy came from (an HF import).

ModelIntakeSource fields
FieldTypeDescription
hf_repostring | null
revisionstring | null

The commit the import read (resolved from a branch or tag).

licensestring | null
filesarray of string
bytesinteger
skippedarray of string

Files of the source repo left out, with why.

RobotCheckJobNeed

object

One open question lucen robot init left in the draft (needs_you), verbatim.

RobotCheckJobNeed fields
FieldTypeDescription
fieldrequiredstring

length ≤ 256

severityrequiredstring

one of blocking · recommended · confirm

blocking refuses Publish; recommended and confirm never do.

whyrequiredstring

length ≤ 2000

namesarray of string

items ≤ 256

suggestionstring | null

length ≤ 1000

RobotCheckJobPublishedFile

object

RobotCheckJobPublishedFile fields
FieldTypeDescription
pathrequiredFilePath
sha256requiredSha256
sizerequiredinteger
linkedrequiredstring

one of deduped · copied

deduped onto bytes the hub had already verified; copied and hashed by the hub.

StorageKey

string

length ≤ 1024

Object storage key (internal, content-addressed for blobs). Not a URL; presign endpoints turn keys into URLs.