Sites running Minn ask here when they check for updates, search the plugin and theme directory, fetch translations and download packages. The answers are wordpress.org's own, served from Minn, so a Minn site never contacts wordpress.org.
POST /v1/plugins/update-check/1.1/ X-Minn-Compat: 7.1 plugins: akismet/akismet.php Version 5.0
new_version: 5.7.2 requires: 5.8 package: https://updates.minn.run/v1/download/plugin/akismet.5.7.2.zip icons: https://updates.minn.run/v1/assets/ps/akismet/assets/icon-128x128.png
The offer is the one wordpress.org makes. Only the addresses change: the site downloads from Minn.
Offers, directory listings and translations match wordpress.org's, checked against the live API request by request.
The first download of a release is fetched from wordpress.org and kept here. Every site after that gets the copy Minn already has.
wordpress.org sees this service asking, never your site's address. Plugins that update from somewhere else never leave Minn.
Endpoints
| POST | /v1/plugins/update-check/1.1/ | Plugin offers for the versions a site has |
| POST | /v1/themes/update-check/1.1/ | Theme offers |
| GET | /v1/plugins/info/1.2/ | Plugin directory: details and search |
| GET | /v1/themes/info/1.2/ | Theme directory: details and search |
| POST | /v1/translations/core/1.0/ | Language packs, also for plugins and themes |
| GET | /v1/download/… | Plugin, theme and translation packages |
| GET | /v1/status | What this service is running |
Next: every release checked file by file against wordpress.org's published checksums before it is offered, and anything suspicious held back from automatic updates.