Skip to content

HTTP API

Every route is prefixed /api/v1 and returns JSON.

The API uses the same session cookie as the web interface. Sign in first, keep the cookie, and send it with each request.

Two levels of access apply. Owner-scoped routes need a signed-in owner — some of those also demand a fresh re-confirmation of the owner password before anything that can destroy or replace the whole install. Workspace-scoped routes additionally need a workspace to have been entered with its master password; without one they return 403 with the error code no_workspace.

123 routes total, grouped as they are in the codebase.

MethodPathWhat it doesScope
GET/auth/sessionCurrent login/session statePublic
POST/auth/loginOwner sign-inPublic
POST/auth/logoutOwner sign-outPublic
POST/auth/change-passwordChange the owner passwordOwner
POST/auth/lockLock the sessionOwner
POST/auth/unlockUnlock the sessionOwner
MethodPathWhat it doesScope
GET/workspacesList workspacesOwner
POST/workspacesCreate a workspaceOwner
POST/workspaces/:id/enterEnter a workspace with its master passwordOwner
POST/workspaces/leaveLeave the active workspaceOwner
DELETE/workspaces/:idDelete a workspaceOwner
GET/admin/overviewInstall-wide overviewOwner
GET/admin/auditAudit logOwner
GET/admin/settingsInstall-level settingsOwner
GET/admin/public-urlCurrent public URL configurationOwner
PUT/admin/public-urlSet the public URLOwner
POST/admin/public-url/testTest the public URL is reachableOwner

One snapshot covers the whole install, so these sit on the owner group rather than any one workspace. See Backup and restore.

MethodPathWhat it doesScope
GET/backup/configCurrent backup schedule/destination configOwner
PUT/backup/configUpdate backup configOwner
POST/backup/runTrigger a snapshot nowOwner
GET/backup/snapshotsList snapshotsOwner
GET/backup/snapshots/:name/downloadDownload a snapshotOwner
DELETE/backup/snapshots/:nameDelete a snapshotOwner
POST/backup/verifyDecrypt and verify a snapshot without restoring itOwner
POST/backup/restoreStage a restore for the next server startOwner

Includes the conversational agent designer FSM, and the approval-gate control surface for connector actions marked public_write.

MethodPathWhat it doesScope
GET/agentsList agentsWorkspace
GET/agents/:idAgent detailWorkspace
DELETE/agents/:idDelete an agentWorkspace
POST/agents/:id/runRun an agent nowWorkspace
GET/agents/:id/run/progressSSE stream of a run in progressWorkspace
GET/agents/:id/runs/:runIDOne run’s transcript — its tool calls and coder turnsWorkspace
PUT/agents/:id/scheduleSet an agent’s cron scheduleWorkspace
DELETE/agents/:id/scheduleRemove an agent’s scheduleWorkspace
PUT/agents/:id/agent-mdOverwrite an agent’s AGENT.mdWorkspace
PUT/agents/:id/skillsSet an agent’s declared skillsWorkspace
PUT/agents/:id/connectionsSet an agent’s bound service connectionsWorkspace
POST/agents/designSend a design-conversation turnWorkspace
POST/agents/design/cancelCancel the in-progress design sessionWorkspace
POST/agents/design/resumeResume a design session after reloadWorkspace
POST/agents/design/dismissDismiss a finished/blocked design sessionWorkspace
GET/agents/design/progressSSE stream of generation progressWorkspace
GET/agents/design/stateCurrent design FSM stateWorkspace
POST/agents/:id/edit/startStart an edit-mode design session for an existing agentWorkspace
PUT/agents/:id/connections/:connID/approvalToggle approve-before-send for one bound connectionWorkspace
GET/approvalsList pending gated connector actionsWorkspace
POST/approvals/:id/approveApprove and send a pending actionWorkspace
POST/approvals/:id/rejectReject a pending actionWorkspace

Covers both stored skills and the conversational skill-designer FSM.

MethodPathWhat it doesScope
GET/skillsList skillsWorkspace
POST/skillsImport/create a skill directlyWorkspace
GET/skills/core/:slugRead a bundled core skill’s contentWorkspace
GET/skills/:idSkill detailWorkspace
PUT/skills/:idUpdate a skillWorkspace
DELETE/skills/:idDelete a skillWorkspace
POST/skills/designSend a design-conversation turnWorkspace
POST/skills/design/cancelCancel the in-progress design sessionWorkspace
POST/skills/design/resumeResume a design session after reloadWorkspace
POST/skills/design/dismissDismiss a finished/blocked design sessionWorkspace
GET/skills/design/progressSSE stream of generation progressWorkspace

Includes the web-search provider keys (Brave/Tavily), which are stored the same way as ordinary secrets.

MethodPathWhat it doesScope
GET/secretsList secret namesWorkspace
POST/secretsCreate/update a secretWorkspace
DELETE/secrets/:nameDelete a secretWorkspace
GET/search-keysWhich web-search provider keys are setWorkspace
PUT/search-keysSet a web-search provider keyWorkspace
DELETE/search-keys/:providerDelete a web-search provider keyWorkspace

Chat-platform connections (Telegram, Discord, Slack) — not to be confused with service connectors, below.

MethodPathWhat it doesScope
GET/connectorsList chat-platform connectionsWorkspace
POST/connectorsAdd a chat-platform connectionWorkspace
DELETE/connectors/:platformRemove a chat-platform connectionWorkspace
POST/connectors/:platform/testTest a chat-platform connectionWorkspace
PUT/connectors/:platform/primarySet the primary chat-platform connectionWorkspace
DELETE/connectors/:platform/identityUnlink a platform identityWorkspace

Self-managed-OAuth and API-key connections to external services — see Connected services.

MethodPathWhat it doesScope
GET/servicesList connected servicesWorkspace
GET/services/:provider/actionsList a provider’s available actionsWorkspace
POST/services/:provider/credsSave a provider’s OAuth app credentialsWorkspace
POST/services/:provider/connectStart an OAuth connect flowWorkspace
POST/services/:provider/apikeyConnect via a pasted API keyWorkspace
DELETE/services/:idDisconnect a service connectionWorkspace

Model Context Protocol servers you added by URL — see MCP servers.

MethodPathWhat it doesScope
GET/mcp/serversList MCP serversWorkspace
POST/mcp/serversAdd an MCP serverWorkspace
GET/mcp/servers/:idServer detailWorkspace
PUT/mcp/servers/:idUpdate a serverWorkspace
DELETE/mcp/servers/:idRemove a serverWorkspace
POST/mcp/servers/:id/testCheck the server answers, and sync its toolsWorkspace
POST/mcp/servers/:id/syncRe-read the server’s tool listWorkspace
GET/mcp/servers/:id/toolsList a server’s discovered toolsWorkspace
PUT/mcp/servers/:id/tools/:toolIDEnable a tool, or change its trust settingsWorkspace
GET/agents/:id/mcpWhich servers an agent is attached toWorkspace
PUT/agents/:id/mcpAttach an agent to serversWorkspace
MethodPathWhat it doesScope
GET/chatsList chatsWorkspace
POST/chatsStart a chatWorkspace
GET/chats/:idChat detail, messages, and whether a turn is in flightWorkspace
PATCH/chats/:idRename/update a chatWorkspace
POST/chats/:id/messagesStart a turn — returns 202 with a turn id, not the replyWorkspace
GET/chats/:id/turn/progressSSE stream of the turn in progressWorkspace
POST/chats/:id/resumeResume a stopped chatWorkspace
POST/chats/:id/stopStop a chatWorkspace
DELETE/chats/:idDelete a chatWorkspace

A chat turn runs on the server, not inside the request that starts it. Sending a message returns immediately with a turn id; the assistant’s reply is written to the chat’s history when the turn finishes, and GET /chats/:id/turn/progress streams what the model is doing in the meantime. That is what lets you close the tab mid-turn and find both your message and the answer waiting when you return — GET /chats/:id reports in_flight so a client that reconnects can pick the turn back up.

Only one turn runs per chat at a time. Sending a second message while one is still working returns 409.

The Home page’s data: reminders, the notification inbox, and the aggregated dashboard summary.

MethodPathWhat it doesScope
GET/remindersList remindersWorkspace
POST/remindersCreate a reminderWorkspace
DELETE/reminders/:idDelete a reminderWorkspace
GET/reminders/pollPoll for due remindersWorkspace
GET/inboxList inbox notificationsWorkspace
GET/inbox/pollPoll for new inbox notificationsWorkspace
POST/inbox/:id/readMark one notification readWorkspace
POST/inbox/read-allMark all notifications readWorkspace
DELETE/inbox/:idDelete a notificationWorkspace
GET/dashboardHome page summary (recent runs, counts)Workspace

The knowledge base — tree, notes, search, assets, export, and the selection-based AI actions (Improve/Proofread/Explain/Reformat).

MethodPathWhat it doesScope
GET/kb/treeFolder/file treeWorkspace
GET/kb/noteRead a noteWorkspace
PUT/kb/noteSave a noteWorkspace
POST/kb/newCreate a note or folderWorkspace
DELETE/kb/noteDelete a noteWorkspace
POST/kb/renameRename/move a note or folderWorkspace
GET/kb/searchSearch the knowledge baseWorkspace
GET/kb/resolveResolve a [[wikilink]] to a pathWorkspace
GET/kb/rawRead a note’s raw bytesWorkspace
PUT/kb/orderSet custom folder orderingWorkspace
POST/kb/uploadUpload a file, converted to markdownWorkspace
PUT/kb/iconSet a folder’s iconWorkspace
GET/kb/foldersList foldersWorkspace
GET/kb/exportExport a note (HTML/PDF/DOCX)Workspace
GET/kb/export/formatsList supported export formatsWorkspace
POST/kb/assetUpload a binary asset (e.g. an image)Workspace
GET/kb/assetsList assetsWorkspace
POST/kb/assistRun an AI action over a selected passageWorkspace
MethodPathWhat it doesScope
GET/settingsCurrent workspace settingsWorkspace
PUT/settings/profileUpdate the user profile (name, timezone, tone, …)Workspace
PUT/settings/workspaceUpdate workspace name/aboutWorkspace
PUT/settings/workspace/iconSet the workspace iconWorkspace
PUT/settings/coderConfigure the coder (local CLI or API engine)Workspace
POST/settings/coder/testTest the configured coderWorkspace
PUT/settings/master-passwordChange the workspace master passwordWorkspace
GET/setupSetup-wizard stateWorkspace
POST/setupComplete a setup-wizard stepWorkspace
GET/setup/platformsList chat platforms available to connect during setupWorkspace
POST/setup/platforms/:platform/testTest a chat-platform connection during setupWorkspace
MethodPathWhat it doesScope
GET/searchGlobal search across agents, skills, chats, and the KBWorkspace