---
name: expose-fmap-worker
description: Publish, inspect, update, or release a Mac mini development service through one of the 24 reserved solar-term HTTPS endpoints under fmap.dev. Use when an Agent needs a public URL for a local HTTP service or needs to diagnose an existing fmap.dev tunnel.
---

# Expose fmap Worker

Use the Worker Gateway API. Do not edit FRP files or LaunchAgents and do not run `frpc` directly.

The current canonical instructions are published at `https://gateway.fmap.dev/skill.md`.

## Bind a service

1. Obtain a user-confirmed free slot from the status response. Do not infer availability from a public HTTP response.
2. Verify that the application listens on `127.0.0.1` without reading or printing its environment files.
3. Create or update the binding:

```bash
curl -fsS http://127.0.0.1:7639/api/v1/slots
curl -fsS -X PUT http://127.0.0.1:7639/api/v1/slots/jingzhe \
  -H 'Content-Type: application/json' \
  --data '{"localPort":7620}'
curl -fsS https://jingzhe.fmap.dev
```

Report the public URL, local port, local service state, and tunnel state.

## Inspect or release

```bash
curl -fsS http://127.0.0.1:7639/api/v1/slots
curl -fsS -X DELETE http://127.0.0.1:7639/api/v1/slots/jingzhe
```

Bindings persist across Worker Gateway restarts. Release a slot only when the user requests cleanup or confirms that the temporary environment is no longer needed.

## Boundaries

- Use only the 24 names returned by the API.
- Use the loopback API for Agent operations. Never request or expose the Web admin token.
- Never read, print, copy, or edit `/Users/bencode/.config/frp/fmap.env`.
- Do not search for, install, replace, or execute FRPC.
- Do not edit generated state, logs, or tunnel configuration.
- If the local API is unavailable, report the failure instead of changing filesystem permissions.
- If FRPS, Caddy, or the public endpoint is unavailable, report the failure; do not mutate the I machine unless explicitly asked.
