curl --request POST \
--url https://app.base44.com/api/apps \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"initial_message": {
"content": "A CRM to track leads and deals"
}
}
'import requests
url = "https://app.base44.com/api/apps"
payload = { "initial_message": { "content": "A CRM to track leads and deals" } }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({initial_message: {content: 'A CRM to track leads and deals'}})
};
fetch('https://app.base44.com/api/apps', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.base44.com/api/apps",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'initial_message' => [
'content' => 'A CRM to track leads and deals'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.base44.com/api/apps"
payload := strings.NewReader("{\n \"initial_message\": {\n \"content\": \"A CRM to track leads and deals\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.base44.com/api/apps")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"initial_message\": {\n \"content\": \"A CRM to track leads and deals\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.base44.com/api/apps")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"initial_message\": {\n \"content\": \"A CRM to track leads and deals\"\n }\n}"
response = http.request(request)
puts response.read_body{
"id": "6820f3a4e7b91d003c45a1f2",
"name": "My CRM",
"slug": "my-crm-3c45a1f2",
"user_description": "A CRM to track leads and deals",
"created_by": "developer@example.com",
"created_date": "2026-08-01T09:15:00",
"updated_date": "2026-08-02T14:30:00",
"status": {
"state": "ready",
"details": "Publishing app",
"request_id": "a1b2c3d4e5f67890abcdef12",
"last_updated_date": "2026-08-02T14:30:00Z",
"error_source": "build",
"paywall_context": {
"billing_organization_id": "67e0b12c4d8a3f005b21c9e4",
"user_id": "6706af53b9c1e2004a37d85f",
"evaluated_at": "2026-08-02T14:30:00Z"
}
},
"last_deployed_at": "2026-08-02T14:30:00",
"screenshot_url": "https://storage.base44.com/screenshots/6820f3a4e7b91d003c45a1f2.png",
"preview_screenshot_url": "https://storage.base44.com/previews/6820f3a4e7b91d003c45a1f2.png",
"main_branch_protected": false,
"organization_id": "67e0b12c4d8a3f005b21c9e4",
"owner_id": "6706af53b9c1e2004a37d85f",
"app_type": "user_app",
"public_settings": "public_with_login",
"auth_config": {
"enable_username_password": true,
"enable_google_login": true,
"enable_microsoft_login": false,
"enable_facebook_login": false,
"enable_apple_login": false
},
"is_remixable": false,
"hide_entity_created_by": true,
"dev_environment_enabled": false,
"logo_url": "https://storage.base44.com/6820f3a4e7b91d003c45a1f2/3f2504e0_logo.png",
"social_image_url": "https://storage.base44.com/6820f3a4e7b91d003c45a1f2/7c9e6679_social.png",
"is_unpublished": false
}Create app
Creates a new app. Pass initial_message.content to build it from a prompt, or send an empty body ({}) to create an empty app. Add initial_message.file_urls to build from a screenshot or a mockup alongside the prompt.
Building from a prompt runs in the background and consumes credits. Poll Get app and watch its status to see when the build finishes. By default the app is created in your default workspace. Set organization_id to create it in another workspace you belong to. This endpoint is limited to 5 requests per minute.
Set name, user_description, public_settings, custom_instructions, secrets, and prevent_iframe_embedding in the same request to configure the app before its first build turn runs. Without a name, the app starts as untitled, and once a build turn changes it Base44 names and describes it, replacing any user_description you sent.
secrets are applied after the app is saved. A request that fails on a secrets entry still leaves the new app in your workspace, and it counts toward your plan’s app limit. Delete it before you retry.curl --request POST \
--url https://app.base44.com/api/apps \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"initial_message": {
"content": "A CRM to track leads and deals"
}
}
'import requests
url = "https://app.base44.com/api/apps"
payload = { "initial_message": { "content": "A CRM to track leads and deals" } }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({initial_message: {content: 'A CRM to track leads and deals'}})
};
fetch('https://app.base44.com/api/apps', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.base44.com/api/apps",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'initial_message' => [
'content' => 'A CRM to track leads and deals'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.base44.com/api/apps"
payload := strings.NewReader("{\n \"initial_message\": {\n \"content\": \"A CRM to track leads and deals\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.base44.com/api/apps")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"initial_message\": {\n \"content\": \"A CRM to track leads and deals\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.base44.com/api/apps")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"initial_message\": {\n \"content\": \"A CRM to track leads and deals\"\n }\n}"
response = http.request(request)
puts response.read_body{
"id": "6820f3a4e7b91d003c45a1f2",
"name": "My CRM",
"slug": "my-crm-3c45a1f2",
"user_description": "A CRM to track leads and deals",
"created_by": "developer@example.com",
"created_date": "2026-08-01T09:15:00",
"updated_date": "2026-08-02T14:30:00",
"status": {
"state": "ready",
"details": "Publishing app",
"request_id": "a1b2c3d4e5f67890abcdef12",
"last_updated_date": "2026-08-02T14:30:00Z",
"error_source": "build",
"paywall_context": {
"billing_organization_id": "67e0b12c4d8a3f005b21c9e4",
"user_id": "6706af53b9c1e2004a37d85f",
"evaluated_at": "2026-08-02T14:30:00Z"
}
},
"last_deployed_at": "2026-08-02T14:30:00",
"screenshot_url": "https://storage.base44.com/screenshots/6820f3a4e7b91d003c45a1f2.png",
"preview_screenshot_url": "https://storage.base44.com/previews/6820f3a4e7b91d003c45a1f2.png",
"main_branch_protected": false,
"organization_id": "67e0b12c4d8a3f005b21c9e4",
"owner_id": "6706af53b9c1e2004a37d85f",
"app_type": "user_app",
"public_settings": "public_with_login",
"auth_config": {
"enable_username_password": true,
"enable_google_login": true,
"enable_microsoft_login": false,
"enable_facebook_login": false,
"enable_apple_login": false
},
"is_remixable": false,
"hide_entity_created_by": true,
"dev_environment_enabled": false,
"logo_url": "https://storage.base44.com/6820f3a4e7b91d003c45a1f2/3f2504e0_logo.png",
"social_image_url": "https://storage.base44.com/6820f3a4e7b91d003c45a1f2/7c9e6679_social.png",
"is_unpublished": false
}Authorizations
Personal access token, sent as Authorization: Bearer <token>.
Body
First prompt to build the app from. Omit to create an empty app.
Show child attributes
Show child attributes
Display name of the app. Omit it to have Base44 name the app once a build turn changes it. The app's URL slug is built from the name.
"My CRM"
Description of the app. When you omit name, Base44 replaces it with a generated description once a build turn changes the app.
"A CRM to track leads and deals"
Who can open the published app. public_without_login lets anyone in, unless the workspace enforces SSO for apps, in which case visitors must log in. public_with_login lets anyone in who logs in, workspace_with_login admits only logged-in members of the workspace, and private_with_login admits only users who were granted access. Omit it to use the workspace default. workspace_with_login and private_with_login need a paid plan, and a workspace policy can restrict which values you can choose. Like other publish settings, it takes effect on the live app once you deploy the app.
public_without_login, public_with_login, workspace_with_login, private_with_login "public_with_login"
Instructions the builder follows on every turn, starting with the first build. Only the first 10,000 characters reach the builder.
"Use a dark theme and keep every page mobile friendly."
Secrets to set on the app before its first build turn, keyed by secret name. Each entry sets the secret to value. The name must not be empty or contain =.
Show child attributes
Show child attributes
{
"STRIPE_API_KEY": {
"type": "value",
"value": "sk_test_example"
}
}
Whether the published app refuses to load inside an iframe on another site. Defaults to true. Set it to false to embed the app, although a workspace embedding policy can still restrict where. Preview URLs are not affected. It takes effect on the live app once you deploy it.
false
ID of the workspace to create the app in. Omit to use your default workspace. You must have an editor-capable role (Editor or above) in the workspace. Viewers and guests cannot create apps. This is the same workspace ID that List apps accepts as workspace_id.
"67e0b12c4d8a3f005b21c9e4"
Response
Successful Response
An app in a workspace, limited to the properties the caller requested.
ID of the app.
"6820f3a4e7b91d003c45a1f2"
Display name of the app.
"My CRM"
URL slug for the app, auto generated from the name and app ID or set to a custom value, or null if the app has no slug yet. The published URL is built from it.
"my-crm-3c45a1f2"
Description of the app, or null if none was set. An app created without a name gets a generated description once a build turn changes it.
"A CRM to track leads and deals"
Email of the user who created the app.
"developer@example.com"
Time the app was created, as a UTC timestamp in ISO 8601 format.
"2026-08-01T09:15:00"
Time the app document was last written, as a UTC timestamp in ISO 8601 format.
"2026-08-02T14:30:00"
The app's current build status. Poll while a build is in progress to watch it finish. This tracks building, not publishing.
Show child attributes
Show child attributes
Time the app was last published, as a UTC timestamp in ISO 8601 format, or null if it has never been published.
"2026-08-02T14:30:00"
URL of a screenshot of the published app. Captured shortly after each publish, so it can briefly lag or be null right after publishing.
"https://storage.base44.com/screenshots/6820f3a4e7b91d003c45a1f2.png"
URL of a preview screenshot taken before publishing, distinct from screenshot_url, or null if none has been captured.
"https://storage.base44.com/previews/6820f3a4e7b91d003c45a1f2.png"
Whether the app's main branch is protected, so changes to main must go through a branch that's merged back. Change it with Set main branch protection.
false
ID of the workspace the app belongs to.
"67e0b12c4d8a3f005b21c9e4"
ID of the user who owns the app. It starts as the creator and changes when ownership is transferred.
"6706af53b9c1e2004a37d85f"
Kind of app, set when it's created. One of user_app (a web app), user_agent (an AI agent), mobile_app (a native mobile app), user_game (a game), slide (a presentation), or imported_app (an app imported from an existing code repository). List apps returns it as stored, so an older agent app can report agent instead of user_agent, and some older apps don't include it. Get app always returns one of the values above.
"user_app"
Who can open the published app. Each value is described under Update app, which also changes it.
public_without_login, public_with_login, workspace_with_login, private_with_login "public_with_login"
Which login methods the app's login page offers. If the workspace enforces SSO for apps, the login page offers only SSO, whatever these are set to. Change them with Update app.
Show child attributes
Show child attributes
Whether others can remix the app. While it's true, the published app also shows the Base44 badge if public_settings is public_with_login or public_without_login.
false
Whether the app's entity records leave out the email of the user who created each one (created_by). Newer apps always leave the email out, whatever this is set to.
true
Whether test data is on, which gives the app a test database next to its live one.
false
URL of the app's logo, or null if it has none. Set it with Set app logo or Generate app logo.
"https://storage.base44.com/6820f3a4e7b91d003c45a1f2/3f2504e0_logo.png"
URL of the image shown when the app is shared on social platforms, or null if none was set, in which case the logo is shown instead. Set it with Set social image.
"https://storage.base44.com/6820f3a4e7b91d003c45a1f2/7c9e6679_social.png"
Whether the app was taken offline with Unpublish app and hasn't been published again since. While it's true, the published URL is offline and last_deployed_at still shows the last publish.
false
Was this page helpful?