SDK reference
Server API
Publish guides kept as JSON in your repository, and delete a user's data, with a secret key.
The server API uses an environment's secret key (ps_sec_…) and acts on that environment only. Keep secret keys on your servers and in CI secrets, never in client code.
curl https://api.playstep.app/v1/server/guides \
-H "Authorization: Bearer $PLAYSTEP_SECRET_KEY" \
-H "Content-Type: application/json" \
-d @guides.json
Publish guides
POST /v1/server/guides validates each guide against the guide spec, saves a new version when it changed, and publishes it. The body is an array of guides or { "guides": [...] }.
{ "published": [{ "id": "create-first-invoice", "version": 4 }] }
Invalid guides return 400 with the problems:
{ "error": "invalid", "issues": [{ "path": ["guides", 0, "steps", 1, "anchor"], "message": "A step that completes on tap needs an anchor" }] }
From the monorepo you can run the same thing with:
PLAYSTEP_SECRET_KEY=ps_sec_dev_… pnpm --filter @playstep/api guides:publish guides/onboarding.json
Unpublish a guide
DELETE /v1/server/guides/:id takes the guide out of this environment. Its versions stay in the dashboard.
Delete a user's data
DELETE /v1/server/users/:userKey deletes the analytics events of one end user. userKey is the SHA-256 hex of the id you passed to identify:
USER_KEY=$(printf '%s' "user_123" | sha256sum | cut -d' ' -f1)
curl -X DELETE "https://api.playstep.app/v1/server/users/$USER_KEY" -H "Authorization: Bearer $PLAYSTEP_SECRET_KEY"
Billing counts keep only the hash for the current period. See data deletion.