HTTP API

Base URL https://addtothese.com/api/v1. Authenticate with Authorization: Bearer att_... (API token) or the browser session plus X-CSRF-Token. All bodies are JSON; errors are {"error": "...", "code": "..."}.

MethodPathPurpose
POST/auth/register{email, password, name}
POST/auth/login{email, password}; may answer {mfa_required: true}
POST/auth/totp/verify{code}
POST/auth/logout
POST/auth/password/forgot | /auth/password/reset{email} | {token, password}
GET/auth/oauth/{google|github}starts OAuth
GET/PATCH/meaccount; PATCH {name}
POST/me/totp/setup | enable | disabletwo-factor
POST/me/password{current_password, new_password}
GET/POST/DELETE/tokens[/{id}]API tokens; POST {name} returns the secret once
GET/POST/DELETE/endpoints[/{id}]POST {subdomain, protocol}
POST/endpoints/ephemeral{protocol} random name
GET/POST/DELETE/domains[/{id}]POST {domain, endpoint_id}
POST/domains/{id}/verifyDNS check
POST/agent-token{endpoints: []} returns {token, upstream_url, endpoints, expires_at}
GET/usagecurrent period and history
GET/tunnelsconnected agents
GET/billing/pricesplans and Stripe prices
POST/billing/checkout | /billing/portal{price} returns {url}