Plugin recipes
How the panel activates pro-plugin licenses (docs/licenses.md). Recipes come from the public catalog, the bundled files or your own JSON; what you enter for their inputs is stored per recipe, and secret inputs such as license keys are never returned.
Reading needs Read only and changes need Full, unless an endpoint says otherwise. How to read this page.
GET /api/recipes
Section titled “GET /api/recipes”Every recipe the panel knows, whether it is installed and enabled, and what is entered for its inputs.
- Level: Read only
- Returns:
{items: [{id, name, plugin, version, source, installed, enabled, sites, inPluginCatalog, inputs: [{id, label, secret, set, display, ...}], ...}]}
POST /api/recipes/local
Section titled “POST /api/recipes/local”Add or replace a recipe of your own; installed and enabled at once, shadows a catalog id.
- Level: Full
- Notes: Destructive
- Input:
{recipe}
GET /api/recipes/:id/definition
Section titled “GET /api/recipes/:id/definition”The recipe as the panel has it, to copy or fork.
- Level: Read only
- Returns:
the recipe JSON
POST /api/recipes/:id/install
Section titled “POST /api/recipes/:id/install”Take a known recipe into use; a catalog recipe keeps following the catalog.
- Level: Full
DELETE /api/recipes/:id/install
Section titled “DELETE /api/recipes/:id/install”Stop using a recipe and forget its key; a local recipe is deleted outright.
- Level: Full
- Notes: Destructive
PUT /api/recipes/:id/enabled
Section titled “PUT /api/recipes/:id/enabled”Switch an installed recipe off or on without uninstalling it.
- Level: Full
- Input:
{enabled}
PUT /api/recipes/:id/inputs/:input
Section titled “PUT /api/recipes/:id/inputs/:input”Enter the value for one of a recipe’s inputs, such as its license key (write-only when secret).
- Level: Full
- Notes: Destructive
- Input:
{value}
DELETE /api/recipes/:id/inputs/:input
Section titled “DELETE /api/recipes/:id/inputs/:input”Forget the value entered for an input.
- Level: Full
- Notes: Destructive
GET /api/catalog
Section titled “GET /api/catalog”The public recipe catalog as this panel sees it: entries, last fetch, last error.
- Level: Read only
- Returns:
{url, entries, unsupported, generatedAt, commit, fetchedAt, changedAt, error, keyId, recipes}
POST /api/catalog/refresh
Section titled “POST /api/catalog/refresh”Fetch and verify the catalog now, ignoring the cached ETag.
- Level: Manage. Only fetches the signed catalog now instead of within the hour
- Returns:
{outcome: "updated"|"unchanged"|"failed"|"disabled", catalog} (sync, <=15 s)