Dialect Desk / API
Get a token

Driving Dialect Desk from code

Everything the web app does is available over HTTP. The base URL is https://api.skillsafe.ai/v1/app-api, every request carries Authorization: Bearer <token>, and every response is the same envelope.

The task field comes first

This app has five lanes behind one endpoint. Every run body must carry a task field naming the lane - it is what the system prompt routes on. Send the wrong one and you get a valid package of the wrong kind; omit it and the model picks the closest lane and tells you which it chose.

One more shape trap: the run body is the input object. Do not wrap it in an {"input": ...} envelope - that returns 200 while hiding task from the model, which is the most confusing way this API can fail.

taskLaneFieldsSections returned
planTurn a table and its queries into a sheetbrief, knownSummary, The Sheet, What It Assumes, Reasoning, Next Step
readEvery difference, sorted by whether it announces itselfsheet, worrySummary, Verdict, Findings, Corrected Sheet, Next Step
nullsThe empty string, NULL, and the queries that cannot tell them apartsheetSummary, Every Combination, What Each Query Returns, What Puts It Back, Next Step
widthsThe widths: a byte limit that becomes a character limitsheetSummary, Every Column, Four Ways, What Crosses The Line, The Checks That Keep The Limit, Next Step
decideDecide what changes: a type, a query, or the application’s mindsheet, fixedSummary, A Target Type Fixes, Only A Rewritten Query Fixes, Nothing Fixes - The Application Has To Decide, The Assertions, Next Step

Only task and the lane’s own required fields are mandatory: sheet on read, nulls, widths and decide; brief on plan. Every field is a string - there are no number fields on this app. sheet is the migration sheet itself: a header of KEY: value lines, then a COLUMNS: block with one column per line, then an EXPRESSIONS: block with the SQL your code runs against those columns.

The header. FROM: and TO: name the two dialects. LENGTH: takes byte or char and is Oracle’s NLS_LENGTH_SEMANTICS; it defaults to byte, and it is the whole width difference - a database created with CHAR semantics has none. COLLATION: is the target database’s collation; C sorts binary, like Oracle, and has no sort difference. ROWS: is the table’s size and scales the counts and nothing else. JOB: is free text for the report.

A column needs a name and an Oracle type and nothing else: customer_name VARCHAR2(40). Everything after that is optional and every one of them changes the answer. notnull matters because in Oracle a NOT NULL VARCHAR2 could not hold '' - the constraint enforced non-emptiness for free. -> target is the PostgreSQL type someone has already chosen; leave it off and the response recommends the value-preserving one instead of judging a choice nobody made. bytecheck means the target comes with CHECK (octet_length(col) <= n), which is the only way varchar(n) can keep a byte limit; notempty means it comes with CHECK (col <> ''). values="a|b|<null>|<empty>" are real sample values, pipe-separated - and they are what turn a shape into a witness: without a value Oracle actually refused, a widening is theory.

An expression line is the SQL as written today, one per line, with the clause word kept - select, where, order by - because it is what tells the reader an ORDER BY is an ORDER BY. Trailing semicolons are ignored.

Everything in the response is sorted by one distinction. A difference is either loud - the statement will not compile, so you find it on the first afternoon from a stack trace - or silent, in which case it compiles, runs, and returns a different value, and you find it from a customer in a quarter. Each expression comes back with a SEVERITY, what Oracle returns, what PostgreSQL returns and the one-line fix. Each column comes back with its target type, whether that type preserves the values, and what it loses if not.

Anything the reader cannot place is listed as a problem rather than skipped: an unknown header key, a line outside a block, a column declared twice, a column with no type and a type whose parentheses cannot be read, each with its line number. A sheet with no readable columns is an error - the type is what decides the target, and the target is what decides whether / truncates and whether the declared length counts bytes or characters.

Byte and character counts come back as integers, a widening as , a truth table as its full 3ⁿ rows with the 3ⁿ − 2ⁿ check beside it. These are rules, not measurements: no database is read and no SQL is run, so Oracle’s behaviour here is documented rather than observed, and the collation ordering comes from Intl.Collator rather than from the glibc or ICU tables PostgreSQL will actually use - the shape of the sort difference is reliable, an exact tie-break between two accented forms is not.

Add $model to any body to choose the model for that run: gpt-5.6-luna, gpt-5.6-terra (the default) or gpt-5.6-sol. Luna caps output at 4,096 tokens and will fail the read, nulls, widths and decide lanes rather than shorten them - a findings table, a corrected sheet, or a truth table with a row per combination, is several thousand characters before the reasoning starts.

The response envelope

Success and failure have the same outer shape, so one check covers both.

{
  "ok": true,
  "data": {
    "...": "the result"
  }
}
{
  "ok": false,
  "error": {
    "code": "VALIDATION_ERROR",
    "message": "seconds should be number, got string",
    "details": {}
  }
}
HTTPerror.codeWhat it means
400VALIDATION_ERRORThe body was not a JSON object, or a declared field had the wrong type. A number field sent as a string is the usual cause.
401UNAUTHORIZEDNo token, or a token that has expired or been revoked. Mint a new one.
402INSUFFICIENT_CREDITSThe balance is below the run's minimum. Call /estimate first and compare hold_credits against /me.
404NOT_FOUNDWrong path, or a job id that does not belong to this token.
409CONFLICTAn Idempotency-Key replay whose body differs from the original request.
429RATE_LIMITEDToo many requests. Back off; do not tight-loop.
503UPSTREAM_UNAVAILABLEThe model provider is unavailable. Retry with backoff.

1. Get a token

Open /tokens.html in a browser and copy the token this app already holds - no developer console needed. A guest token is minted automatically and is enough for /me and /estimate; writing a package is metered and needs a personal token, which comes from signing in on that page.

Keep it in an environment variable rather than in source:

export SKILLSAFE_TOKEN="YOUR_TOKEN"

2. Check the session and the balance

GET /me is free. It returns only three fields: subject_type, subject_id and credits. Signed-in means subject_type == "user" - there is no username or email to test.

curl -sS -X GET "https://api.skillsafe.ai/v1/app-api/me" \
  -H "Authorization: Bearer $SKILLSAFE_TOKEN"

3. Price the run before making it

POST /estimate costs nothing, creates no job, and returns the worst-case cost. Compare hold_credits against the balance from step 2 before you submit: a 402 after the fact is avoidable. hold_credits is a reservation priced at the full output cap - the actual charge is usually far lower.

It also echoes model, model_alias and markup_bps, which is the authoritative check that a run is bound to the model you think it is. Estimate each lane separately: their prompts and caps differ, so their holds do.

curl -sS -X POST "https://api.skillsafe.ai/v1/app-api/estimate" \
  -H "Authorization: Bearer $SKILLSAFE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "task": "read",
  "sheet": "<FROM/TO/LENGTH/COLLATION header, a COLUMNS block with one column per line, then an EXPRESSIONS block; the grammar is in /llms.txt>",
  "worry": "the display names came out blank for about a fifth of the customers",
  "rules": "<the working rules for this lane, sent by the app>"
}'

4. Write a package

POST /run submits the job. Always send an Idempotency-Key: a network blip that replays the same request must not bill twice. A replay with the same key returns the stored result and is not charged again; a replay with the same key but a different body is a 409.

The response carries output.output (the Markdown package), charged_credits and truncated. If truncated is true the balance sat between min_credits and hold_credits and the output was cut short - render what arrived and say so rather than presenting it as complete.

curl -sS -X POST "https://api.skillsafe.ai/v1/app-api/run" \
  -H "Authorization: Bearer $SKILLSAFE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "task": "read",
  "sheet": "<FROM/TO/LENGTH/COLLATION header, a COLUMNS block with one column per line, then an EXPRESSIONS block; the grammar is in /llms.txt>",
  "worry": "the display names came out blank for about a fifth of the customers",
  "rules": "<the working rules for this lane, sent by the app>"
}'

5. Stream a run

POST /run-stream is the same call with a text/event-stream response. Worth knowing before you build on it: from a server or from cURL you get event: delta frames carrying the output token by token; from a browser you get event: tick heartbeats and then one event: done with the whole output. Handle both, and treat ticks as liveness rather than progress.

Frame types are job (the job id), delta ({"text": "..."}), tick ({"t": seconds}), done, and error. An idempotent replay returns plain JSON with no stream at all, so check the content type before you start reading frames.

curl -sS -N -X POST "https://api.skillsafe.ai/v1/app-api/run-stream" \
  -H "Authorization: Bearer $SKILLSAFE_TOKEN" \
  -H "Content-Type: application/json" \
  -H "Accept: text/event-stream" \
  -H "Idempotency-Key: cbd-$(date +%s)" \
  -d '{
  "task": "read",
  "sheet": "<FROM/TO/LENGTH/COLLATION header, a COLUMNS block with one column per line, then an EXPRESSIONS block; the grammar is in /llms.txt>",
  "worry": "the display names came out blank for about a fifth of the customers",
  "rules": "<the working rules for this lane, sent by the app>"
}'

6. Read the result

output.output is Markdown in the envelope this app's system prompt guarantees: every section is a level-two heading spelled exactly as listed in the lane table above, in that order; tables are GitHub pipe tables with the declared columns; prompts are in fenced blocks opened with three backticks and the word text; checklists are - [x] lines.

So parsing is a split on /^## / - but do it fence-aware, because a prompt block can legitimately contain a line starting with ##. Count the sections you got against the ones the lane declares: a short list means the run was truncated, not that the contract changed.

def sections(md):
    out, name, buf, fence = {}, None, [], False
    for line in md.split("\n"):
        if line.lstrip().startswith("```"):
            fence = not fence
        if not fence and line.startswith("## "):
            if name:
                out[name] = "\n".join(buf).strip()
            name, buf = line[3:].strip(), []
            continue
        if name:
            buf.append(line)
    if name:
        out[name] = "\n".join(buf).strip()
    return out

The artifact most callers want is the fenced text block inside ## The Sheet or ## Corrected Sheet - that is a complete sheet in the grammar above, so it can be fed straight back into another lane with nothing carried alongside it. Every other section is prose and tables meant to be read.

Rate limits and good manners