Skip to content

Automate test dependencies

Everything on the Dependencies tab is available without the console. This page lists the REST routes, the MCP tools and the skill behavior, and explains how a builder field refers to a dependency.

Every request needs an Authorization: Bearer <your-key> header (a console session token or an mpak_ API key) and an X-Account-Id: <account-id> header. The base URL is https://app.maxoperf.com/v1. The test, secret and entity ids come from the console URLs or from the list routes.

# List a test's dependencies
GET /v1/tests/{testId}/dependencies
# Replace a test's manual secret bindings
PUT /v1/tests/{testId}/secret-bindings
# Bind, update or remove a virtual service
PUT /v1/virtual-services/bindings
DELETE /v1/virtual-services/bindings/{bindingId}
# Bind, update or remove a tunnel
PUT /v1/tests/{testId}/dependencies/tunnels/{tunnelId}
DELETE /v1/tests/{testId}/dependencies/tunnels/{tunnelId}
# Bind, update or remove a browser fleet
PUT /v1/tests/{testId}/dependencies/browser-fleets/{fleetId}
DELETE /v1/tests/{testId}/dependencies/browser-fleets/{fleetId}
# See what uses an entity
GET /v1/dependencies/usage?kind=<kind>&entityId=<id>
# See a run's leases
GET /v1/runs/{runId}/dependencies

PUT on a binding is an upsert: calling it again with the same test and entity changes the variable name. A stem that is not upper-snake, or is longer than 40 characters, is rejected with invalid_env_var_name.

PUT /v1/tests/{testId}/secret-bindings replaces the test’s manually bound secrets with the list you send, so include the ones you want to keep. Bindings that the test’s model creates inline are not touched. envName must match ^SECRET_[A-Za-z0-9_]{1,120}$. Leave it out to inject the secret under its own name.

Terminal window
curl -X PUT https://app.maxoperf.com/v1/tests/tst-0123456789/secret-bindings \
-H "Authorization: Bearer <your-key>" \
-H "X-Account-Id: <account-id>" \
-H "Content-Type: application/json" \
-d '{ "bindings": [ { "secretId": "sec-0123456789", "envName": "SECRET_PAYMENTS_API_KEY" } ] }'

autoStart defaults to true.

Terminal window
curl -X PUT https://app.maxoperf.com/v1/virtual-services/bindings \
-H "Authorization: Bearer <your-key>" \
-H "X-Account-Id: <account-id>" \
-H "Content-Type: application/json" \
-d '{ "testId": "tst-0123456789", "virtualServiceId": "vs-0123456789", "envVarName": "PAYMENTS", "autoStart": true }'

The response includes injectedEnvName, here MAXOPERF_VS_PAYMENTS_URL.

Terminal window
curl -X PUT https://app.maxoperf.com/v1/tests/tst-0123456789/dependencies/tunnels/tun-0000000001 \
-H "Authorization: Bearer <your-key>" \
-H "X-Account-Id: <account-id>" \
-H "Content-Type: application/json" \
-d '{ "envVarName": "SHOP" }'
Terminal window
curl -X PUT https://app.maxoperf.com/v1/tests/tst-0123456789/dependencies/browser-fleets/flt-0000000001 \
-H "Authorization: Bearer <your-key>" \
-H "X-Account-Id: <account-id>" \
-H "Content-Type: application/json" \
-d '{ "envVarName": "EU" }'

The response lists the four injectedEnvNames. A fleet binding has no autoStart field.

Terminal window
curl "https://app.maxoperf.com/v1/dependencies/usage?kind=secret&entityId=sec-0123456789" \
-H "Authorization: Bearer <your-key>" \
-H "X-Account-Id: <account-id>"

kind is secret, virtual_service, tunnel or browser_fleet. The response lists the tests that bind the entity with their variable names and origin, a hiddenCount for tests you cannot view, and the liveRuns that hold it.

ToolUse
list_test_dependenciesEvery binding a test has, plus a read-only data summary and shadowing warnings.
bind_test_dependencyBind a secret, virtual service, tunnel or browser fleet. env_var_name is required except for secrets. auto_start applies to virtual services only.
unbind_test_dependencyRemove the test’s own manual binding.
get_run_dependenciesA run’s leases, with state and timestamps. Secrets are not listed.
get_dependency_usageThe tests and live runs that use an entity. Call it before you delete or stop one.
set_eux_probeSet or clear the browser test that runs next to a performance test.

The full argument tables are on MCP tools.

The MaxoPerf skill uses the same tools. When a test needs a credential, it creates the workspace secret, binds it with bind_test_dependency and tells the script to read the resulting variable instead of a literal. It checks get_dependency_usage before it deletes or stops a dependency. It never repeats a secret’s value in the chat.

In the HTTP request builder, click Use dependency beside the URL field and pick a virtual service or tunnel. The field then holds a chip instead of typed text, and a small Env var name field under it sets the stem. The binding appears on the Dependencies tab marked Used in the test model and is removed by editing the model, not from the tab. A browser step’s value field offers the same picker for virtual services and tunnels.

The builder writes a placeholder such as ${MAXOPERF_RUNTIME__MAXOPERF_VS_PAYMENTS_URL}. Every runner exports each injected variable twice: under its own name, and under the same name with a MAXOPERF_RUNTIME__ prefix. A script reads the plain name. The builder’s rendered requests use the prefixed one. Prefer the chip to typing the placeholder yourself: it creates the binding, and a run refuses to start with a 400 when a chip’s binding has been removed, instead of sending an unresolved placeholder.

A virtual service chip in the request URL field. The Dependencies tab marks the binding Used in the test model.