Skip to content
How to install

Panel login

The browser session, not the API. A key needs none of this: it is a separate credential that two-factor never gates.

Reading needs Read only and changes need Full, unless an endpoint says otherwise. How to read this page.

Sign in; totpRequired means the cookie is only half a login.

  • Level: No key
  • Notes: Not over MCP
  • Input: {username, password}

Finish a half-login with a code or recovery code.

  • Level: No key
  • Notes: Not over MCP
  • Input: {code}

End this session.

  • Level: Full
  • Notes: Not over MCP

Email a reset link to the account’s confirmed address; answers the same either way.

  • Level: No key
  • Notes: Not over MCP
  • Input: {login}
  • Returns: {ok: true}

Set a new password with the token from a reset link; ends every session of the account.

  • Level: No key
  • Notes: Not over MCP
  • Input: {token, newPassword}
  • Returns: {ok: true, username}

Make a pending address the recovery email, with the token from its link.

  • Level: No key
  • Notes: Not over MCP
  • Input: {token}
  • Returns: {username, email}

End every session of the signed-in admin; keys and other admins are untouched.

  • Level: Full
  • Notes: Destructive · Not over MCP

Who this request is: the admin behind a session, or null for a key.

  • Level: Read only
  • Notes: Not over MCP
  • Returns: {user, authVia}