API reference

Contract source

arlesfarias/l3backups.com

Application version
2.1.0
API version
1.0.0
Revision
93de3d9c6f455ffc4678fc41a400b805bdd81594
SHA-256
9e76e40b0416f10ee94361525456a9b0e2852871b03daa2a43ba59759d39ff73

Download OpenAPI contract · API 1.0.0

Descriptions follow the official contract. Identifiers and JSON examples are preserved; the download contains the original.

Overview, authentication and limits

Public API v1 (released). Use the tenant HTTPS host. Only Authorization: Bearer authenticates requests; browser cookies are ignored. Credentials are opaque, not JWTs. Expiration, revocation, independent action permissions and current resource access are checked against persistence on every request. Selected groups authorize their current members, in union with individually selected devices. No action permission implies another. Resources outside the tenant or token's scope return 404. All processed calls in an identified tenant are audited before data or mutations are released; persistence failures fail closed with 503. No credentials, commands or storage URLs are exposed. Default shared limits per fixed one-minute window: 30 attempts per origin/tenant before authentication (including valid requests), 120 requests per token, 600 per tenant. Backend configuration may change these limits. 429 includes Retry-After in seconds. Revocation blocks new calls; accepted work continues. Rotation immediately invalidates old credentials. Tenant lifecycle, billing and SSH trust restrictions remain authoritative. Additive changes are allowed in v1; incompatible changes require documented deprecation and a new API version. The OpenAPI version does not change /api/v1.

Operations

Loading reference…