API Preview
Explore Citadel's public API endpoints, request parameters, and response schemas.
Use the public API to integrate Citadel with scripts and developer tools. This API Preview documents the public contract; use the schema matching your installed version when building integrations.
Authentication and trying requests
Protected operations use an Authorization: Bearer <token> header. Depending on the
operation, use a user JWT or a Service Account token with the required access.
For an integration, prefer a dedicated Service Account
with narrowly scoped permissions. Service Accounts require the Custom Access
Control license capability. User JWTs remain subject to the operation's own
permissions and capability requirements. Keep tokens out of source files and logs.
This reference does not send API requests or store credentials. To try requests
against your own installation, set EnableSwagger=true in .env and recreate
Core with docker compose up -d server. Include your TLS overlay if you use one.
Swagger UI is then available at /swagger/, with the public schema at
/openapi/public/v1.json.
The full schema used by Citadel's web UI is internal and is not the external contract. Read the release notes before upgrading an integration.
Loading API reference…