API conventions
Use the appliance’s versioned HTTP API and its own OpenAPI reference.
API location
The API is served at /api/v1/..., with /api/... as an alias. On your appliance, open /api/docs for the rendered reference or /api/openapi.json for the schema.
Authentication and permissions
Protected API routes require a session or an API token and enforce their applicable permissions. Authentication endpoints and health probes have their own access rules. Pass an API token using the Authorization header:
Authorization: Bearer <your-api-token>Use the installed contract
The schema distinguishes routes with a declared contract using x-cenovel-contract: documented and marks other routes as undocumented. Consult the schema on the installed release for its parameters, response fields, and permissions.
An unsupported path version or Accept-Version header returns 406 with the supported versions.
Read the operator reference
8. API reference
The API supports /api/v1/... and the /api/... alias. /api/docs renders the
installed API reference; /api/openapi.json returns its OpenAPI schema.
Protected routes require a session or API token and their applicable
permissions. Authentication endpoints and health probes have their own rules.
Authorization: Bearer <your-api-token>
Routes with declared contracts are marked x-cenovel-contract: documented;
other routes are marked undocumented. Consult the installed schema for
parameters, response fields, and permissions. Unsupported path versions or
Accept-Version headers return 406 with the supported versions.Reviewed against the current source code. Native appliance administration commands require the appropriate host privileges; validate deployment procedures on your own release before production use.