## Get version metadata

`GET /v1/apps/:id/sources/:versionId`

Returns the metadata of one version of the application's source code, without the archive. Use it when the version identifier is already known and there is no reason to fetch the whole list.

The operation stays available even when source saving is disabled: the previously saved history remains readable.

## Parameters

| Parameter | Type | Required | Description |
|----------|-----|:-----:|----------|
| `id` (path) | UUID | yes | Application identifier. Get it via [`GET /v1/apps`](/docs/apps/list). |
| `versionId` (path) | string | yes | Version identifier of the form `v<N>`. Get it via [List versions](/docs/source-storage/versions). The `savedVersionId` returned by a [deploy](/docs/infra/deploy/deploy) to a server on a personal key belongs to the server's history, not the application's: with it, this method returns a different application version or `404 VERSION_NOT_FOUND`. Request that version via the [server endpoints](/docs/source-storage/servers). |

## Examples

### curl — personal key

```bash
curl -H "X-Api-Key: YOUR_API_KEY" \
  https://vibecode.bitrix24.com/v1/apps/<APP_ID>/sources/v1
```

### curl — OAuth application

```bash
curl -H "X-Api-Key: YOUR_APP_KEY" \
  -H "Authorization: Bearer USER_SESSION_TOKEN" \
  https://vibecode.bitrix24.com/v1/apps/<APP_ID>/sources/v1
```

### JavaScript — personal key

```javascript
const res = await fetch(
  `https://vibecode.bitrix24.com/v1/apps/${appId}/sources/v1`,
  { headers: { 'X-Api-Key': 'YOUR_API_KEY' } },
)
const { data } = await res.json()
console.log(data.versionId, data.tags, data.note)
```

### JavaScript — OAuth application

```javascript
const res = await fetch(
  `https://vibecode.bitrix24.com/v1/apps/${appId}/sources/v1`,
  {
    headers: {
      'X-Api-Key': 'YOUR_APP_KEY',
      'Authorization': 'Bearer USER_SESSION_TOKEN',
    },
  },
)
const { data } = await res.json()
console.log(data.versionId, data.tags, data.note)
```

## Response fields

This response carries no `data.id`: the internal record identifier is returned only on save.

| Field | Type | Description |
|------|-----|----------|
| `success` | boolean | Always `true` on success. |
| `data.versionId` | string | Version identifier of the form `v<N>`. |
| `data.filename` | string | Filename in storage. Contains a `-published` or `-manual` suffix based on the version's current tags; with both tags, `-published`. |
| `data.contentType` | string \| null | The type the archive was saved with: `application/gzip`, `application/x-tar`, `application/zip`, or `application/octet-stream`. `null` for early versions whose type was not recorded. |
| `data.timestamp` | string | Save time (ISO 8601, UTC). |
| `data.size` | number | Archive size in bytes. |
| `data.sha256` | string | SHA-256 of the archive contents. Used for deduplication within one owner. |
| `data.tags` | string[] | Version tags. `manual` and `published` protect the version from automatic cleanup; any other tags are free-form labels from the `X-Tags` header at [save](/docs/source-storage/save) time or from [`PATCH`](/docs/source-storage/metadata#update-version-metadata). |
| `data.savedBy.userId` | string \| null | Vibecode user identifier. |
| `data.savedBy.session` | string \| null | AI session identifier from the `X-AI-Session-Id` header. |
| `data.linkedDeployId` | string \| null | Marker of the latest event involving the version. `deploy:…` — the version was saved or confirmed by a deploy. `publish:<time>` — the version was published via [`POST /v1/apps/:id/publish`](/docs/apps/publish). Publishing overwrites the deploy marker. `null` — the version has had neither a deploy nor a publication. |
| `data.deployStatus` | string \| null | How the latest deploy of this version ended: `success` or `failed`. `null` if the version has never been deployed — for example, if it was saved manually and never passed to a deploy as [`source.versionId`](/docs/infra/deploy/deploy). Publishing does not change this field, but on some older published versions `success` was set by the publication, not by a deploy. |
| `data.note` | string \| null | Note from the `X-Note` header at [save](/docs/source-storage/save) time or from [`PATCH`](/docs/source-storage/metadata#update-version-metadata). For a version saved by a deploy, it holds the deploy's `changelog` field or, without one, the service string `Auto-saved on deploy …` with the same deploy marker as in `linkedDeployId`. |
| `data.serverContext` | object \| null | The server managed by this application's key (`vibe_app_*`), if the version is linked to one. Server data is current as of the request. `null` if the version is not linked to a server. |
| `data.serverContext.serverId` | string | Server identifier. Get it via [`GET /v1/infra/servers`](/docs/infra/servers/list). |
| `data.serverContext.serverName` | string | System name of the server. |
| `data.serverContext.serverDisplayName` | string | Display name of the server. An empty string if the server has none. |
| `data.serverContext.linkedApp` | object \| null | The application the server's managing key is issued for. `null` if the server is managed by a personal key. |
| `data.serverContext.linkedApp.appId` | string | Application identifier. Get it via [`GET /v1/apps`](/docs/apps/list). |
| `data.serverContext.linkedApp.title` | string | Application title. |

## Response example

`HTTP 200`:

```json
{
  "success": true,
  "data": {
    "versionId": "v1",
    "filename": "2026-08-04T10-01-25-947Z-v1.tar.gz",
    "contentType": "application/gzip",
    "timestamp": "2026-08-04T10:01:25.947Z",
    "size": 49504,
    "sha256": "e28aaf8af203804c934e6881c94472a420174f58c9442ecef82dba44c6cf989b",
    "tags": [],
    "savedBy": {
      "userId": "48bdfd33-5fbe-4ad1-a02c-9b5c7ae65f77",
      "session": null
    },
    "linkedDeployId": null,
    "deployStatus": null,
    "note": "First version",
    "serverContext": null
  }
}
```

## Error response example

404 — the application has no version with that identifier:

```json
{
  "success": false,
  "error": {
    "code": "VERSION_NOT_FOUND",
    "message": "Version v99 not found"
  }
}
```

## Errors

| HTTP | Code | Description |
|------|-----|----------|
| 400 | `INVALID_VERSION_ID` | The `versionId` format does not match `v<non-negative integer>`. |
| 403 | `SOURCE_APP_ID_MISMATCH` | The call was made with an authorization key `vibe_app_…` issued for a different application. Such a key can access only its own application's snapshots, even when both applications were created by the same author. |
| 403 | `NOT_AUTHORIZED` | The personal key belongs neither to the application author nor to a Bitrix24 account administrator and was not issued for this application. |
| 404 | `APP_NOT_FOUND` | The application does not exist, was deleted, or belongs to another portal. |
| 404 | `VERSION_NOT_FOUND` | A version with this `versionId` does not exist or was deleted. |

Full list of common API errors — [Errors](/docs/errors).

## See also

- [Source code storage](/docs/source-storage)
- [List versions](/docs/source-storage/versions)
- [Download the archive](/docs/source-storage/versions-download)
- [Version tags and notes](/docs/source-storage/metadata)
- [Save a snapshot](/docs/source-storage/save)
- [Server-keyed source endpoints](/docs/source-storage/servers)
