> ## Documentation Index
> Fetch the complete documentation index at: https://docs.decimal.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Roll back to a prior manifest — one-click oncall mitigation

> One-click rollback to a prior manifest version.

Closes discovery/cuj17_oncall_paged_3am/no-manifest-rollback-endpoint
(filed at improve#609, consumed improve#610). Pre-fix oncall users
had to (1) look up the previous manifest_id, (2) re-register with
that hash, (3) hope the auto-revert path inside `register_manifest`
catches it. That's 3-step cognitive work at 3am. Now: one POST.

Flow:
  1. Load the target manifest. Org-scoped (404 if not in caller's org).
  2. If target is already `status=active`, return 400.
  3. Find the current active manifest for the same agent.
  4. Atomically: mark current_active = 'superseded', target = 'active'.
  5. Write an AuditLog row with action='manifest.rollback', target_id=
     the manifest being deactivated, metadata=which manifest is now active.
  6. Return the now-active manifest.

Optional body: `{"reason": "..."}` is recorded in audit_log.metadata_json.



## OpenAPI

````yaml /openapi.json post /api/v1/manifests/{manifest_id}/rollback
openapi: 3.1.0
info:
  title: DecimalAI Platform
  description: Agent Dataset Lifecycle Platform — Backend API
  version: 0.1.0
servers: []
security:
  - BearerAuth: []
tags:
  - name: traces
    description: >-
      Ingest, search, and inspect agent execution traces. A trace is the atomic
      unit of the platform — every other feature (evaluation, compatibility
      scoring, dataset building) operates on traces. Each trace is auto-tagged
      with the manifest hash of the agent that produced it.
  - name: eval-scores
    description: >-
      Push, fetch, and aggregate per-trace evaluation scores. Scores carry
      source provenance (built-in, DeepEval, LangSmith, custom) and feed the
      unified decision engine, which produces a keep / repair / replay / drop
      verdict per trace.
  - name: skills
    description: >-
      Manage reusable instruction blocks (SKILL.md files) that modify agent
      behavior. Skills are first-class manifest components — changes to a skill
      appear in your regression-check impact reports. Use these endpoints to
      create, version, fork, and sync skills with your local SKILL.md files.
  - name: manifests
    description: >-
      Register and inspect manifest versions. A manifest is a snapshot of your
      agent's structural identity (tools, prompts, models, skills) at a point in
      time. The SDK registers manifests automatically; these endpoints expose
      the underlying records.
  - name: datasets
    description: >-
      Build versioned SFT/DPO training datasets from manifest-classified,
      eval-scored traces. Datasets are reproducible — each version locks the
      manifest and filter set used to build it. Export as JSONL, Parquet, or
      push to HuggingFace Hub.
  - name: replay
    description: >-
      Re-execute historical traces against a new manifest version. Replay is the
      deferred-future capability for behavioral verification of agent changes.
      The SDK creates a replay batch, your worker executes each task, then
      submits results back here for eval scoring.
  - name: registry
    description: >-
      Browse and install community skills from the public skills registry. Each
      registry skill carries a SkillScore — an evidence-tiered quality composite
      computed from real-world evals, benchmarks, and ratings across
      organizations. Installing creates a fork in your org — edits don't affect
      the public version.
  - name: agents
    description: >-
      List and inspect agents, plus their multi-agent topology (orchestrator →
      sub-agent edges discovered from traces). Agents are identified by a stable
      agent_name string set in your SDK init() call.
  - name: import
    description: >-
      Bulk-import historical traces from another observability platform or a
      JSONL backup. Useful for migrating from LangSmith / Braintrust / Langfuse.
      Duplicate trace IDs are silently skipped — re-running an import is safe.
paths:
  /api/v1/manifests/{manifest_id}/rollback:
    post:
      tags:
        - manifests
      summary: Roll back to a prior manifest — one-click oncall mitigation
      description: >-
        One-click rollback to a prior manifest version.


        Closes discovery/cuj17_oncall_paged_3am/no-manifest-rollback-endpoint

        (filed at improve#609, consumed improve#610). Pre-fix oncall users

        had to (1) look up the previous manifest_id, (2) re-register with

        that hash, (3) hope the auto-revert path inside `register_manifest`

        catches it. That's 3-step cognitive work at 3am. Now: one POST.


        Flow:
          1. Load the target manifest. Org-scoped (404 if not in caller's org).
          2. If target is already `status=active`, return 400.
          3. Find the current active manifest for the same agent.
          4. Atomically: mark current_active = 'superseded', target = 'active'.
          5. Write an AuditLog row with action='manifest.rollback', target_id=
             the manifest being deactivated, metadata=which manifest is now active.
          6. Return the now-active manifest.

        Optional body: `{"reason": "..."}` is recorded in
        audit_log.metadata_json.
      operationId: rollback_manifest_api_v1_manifests__manifest_id__rollback_post
      parameters:
        - name: manifest_id
          in: path
          required: true
          schema:
            type: string
            title: Manifest Id
        - name: Authorization
          in: header
          required: false
          schema:
            type: string
            title: Authorization
        - name: decimal_session
          in: cookie
          required: false
          schema:
            anyOf:
              - type: string
              - type: 'null'
            title: Decimal Session
      requestBody:
        content:
          application/json:
            schema:
              anyOf:
                - additionalProperties: true
                  type: object
                - type: 'null'
              title: Payload
      responses:
        '200':
          description: Rolled back successfully
          content:
            application/json:
              schema: {}
        '400':
          description: Manifest already active or invalid rollback target
        '404':
          description: Manifest not found
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
components:
  schemas:
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
        input:
          title: Input
        ctx:
          type: object
          title: Context
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: Enter your API key (e.g. dai_sk_test_key_001)

````