> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fourdos.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a private module version draft

> Only the owning organization can create a version for its private module. The manifest is checked against the platform module contract when the version is published, not when this draft is created.



## OpenAPI

````yaml https://api.develop.fourdos.dev/openapi/partner.json post /v1/modules/{moduleId}/versions
openapi: 3.1.0
info:
  title: 4D OS Partner API
  version: 0.1.0
  description: >-
    REST API for 4D OS partners. Authenticate with your organization API key:
    `Authorization: Bearer <key>`.


    Requests and responses are JSON with `snake_case` field names. Errors share
    one envelope: `{ "error": { "code", "status", "message", "details"? } }`.


    Mutating endpoints that declare it accept an `Idempotency-Key` header so
    retries are safe.


    Bulk-migrating members? See the [Migrating to 4D
    guide](https://docs.fourdos.dev/walkthroughs/migrate-existing-members) for
    the canonical import schema, a worked example, and the `/v1/imports`
    sequence.
servers:
  - url: https://api.develop.fourdos.dev
security:
  - partnerApiKey: []
tags:
  - name: Users
    description: Create, read, and manage users and their org membership
  - name: Imports
    description: Bulk member import jobs (staging → validate → commit)
  - name: API keys
    description: Issue, list, and revoke server-side organization API keys
  - name: Modules
    description: >-
      Publish private modules, install visible modules, and manage their
      credentials
  - name: Ingest
    description: Receive signed native events from an installed module
  - name: Engagement
    description: Browser event tracking (publishable keys) and tracking-key management
paths:
  /v1/modules/{moduleId}/versions:
    post:
      tags:
        - Modules
      summary: Create a private module version draft
      description: >-
        Only the owning organization can create a version for its private
        module. The manifest is checked against the platform module contract
        when the version is published, not when this draft is created.
      operationId: createModuleVersion
      parameters:
        - name: moduleId
          in: path
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateModuleVersionBody'
      responses:
        '201':
          description: Module version draft created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ModuleVersionResponse'
        '401':
          description: Authentication is required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Only the owning organization can manage this private module
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Module not found or not visible to this organization
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: This version already exists for the module
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '422':
          description: Validation error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - adminSession: []
components:
  schemas:
    CreateModuleVersionBody:
      type: object
      properties:
        version:
          type: string
          minLength: 1
          maxLength: 64
        manifest:
          type: object
          propertyNames:
            type: string
          additionalProperties: {}
      required:
        - version
    ModuleVersionResponse:
      type: object
      properties:
        id:
          type: string
        module_id:
          type: string
        version:
          type: string
        manifest:
          type: object
          propertyNames:
            type: string
          additionalProperties: {}
        status:
          type: string
          enum:
            - draft
            - published
            - retired
        published_at:
          anyOf:
            - type: string
            - type: 'null'
        created_at:
          type: string
        updated_at:
          type: string
      required:
        - id
        - module_id
        - version
        - manifest
        - status
        - published_at
        - created_at
        - updated_at
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
            status:
              type: integer
            message:
              type: string
            details:
              type: object
              additionalProperties: true
          required:
            - code
            - status
            - message
      required:
        - error
  securitySchemes:
    partnerApiKey:
      type: http
      scheme: bearer
      description: >-
        Organization API key (`org_...`) sent as `Authorization: Bearer <key>`.
        Keys are scoped to one organization; every request operates within that
        tenant.
    adminSession:
      type: http
      scheme: bearer
      description: >-
        Partner admin session token sent as `Authorization: Bearer <token>`.
        Obtained by signing in (console or the email OTP endpoints) and
        completing the second factor; see the Authentication page.

````