Offsite destinations
Credentials are write-only: they go in with secrets and read back as secretsSet - the names on file, never the values.
Reading needs Read only and changes need Full, unless an endpoint says otherwise. How to read this page.
GET /api/backup-destinations
Section titled “GET /api/backup-destinations”List destinations.
- Level: Read only
- Returns:
{items}
POST /api/backup-destinations
Section titled “POST /api/backup-destinations”Add a destination; with encryption on, the passphrase comes back exactly once.
- Level: Full
- Input:
{name, provider, config, secrets, enabled?, copyTypes?, retention*, encryption?, backfill?} - Returns:
201 Destination
POST /api/backup-destinations/test
Section titled “POST /api/backup-destinations/test”Probe unsaved credentials: listing, write, delete.
- Level: Full
- Returns:
{ok, checks[]}
POST /api/backup-destinations/:id/test
Section titled “POST /api/backup-destinations/:id/test”The same with the stored credentials.
- Level: Manage. Only tests the stored credentials; changes nothing
PATCH /api/backup-destinations/:id
Section titled “PATCH /api/backup-destinations/:id”Change a destination (provider is immutable; encryption is fixed once a copy exists).
- Level: Full
- Notes: Destructive
POST /api/backup-destinations/:id/passphrase
Section titled “POST /api/backup-destinations/:id/passphrase”Read the crypt passphrase back - the one endpoint that returns a stored secret.
- Level: Full
- Notes: Destructive
- Returns:
{password, salt}
GET /api/backup-destinations/:id/copies
Section titled “GET /api/backup-destinations/:id/copies”Copies made to this destination.
- Level: Read only
- Input:
?status=&limit=&offset=
DELETE /api/backup-destinations/:id
Section titled “DELETE /api/backup-destinations/:id”Forget a destination; with deleteRemote, purge what this panel wrote there.
- Level: Full
- Notes: Destructive
- Input:
?deleteRemote=true|false (default false)