Citadel

API Preview

Explore Citadel's public API endpoints, request parameters, and response schemas.

Use the public API to integrate Citadel with scripts and developer tools. This API Preview documents the public contract; use the schema matching your installed version when building integrations.

Authentication and trying requests

Protected operations use an Authorization: Bearer <token> header. Depending on the operation, use a user JWT or a Service Account token with the required access. For an integration, prefer a dedicated Service Account with narrowly scoped permissions. Service Accounts require the Custom Access Control license capability. User JWTs remain subject to the operation's own permissions and capability requirements. Keep tokens out of source files and logs.

This reference does not send API requests or store credentials. To try requests against your own installation, set EnableSwagger=true in .env and recreate Core with docker compose up -d server. Include your TLS overlay if you use one. Swagger UI is then available at /swagger/, with the public schema at /openapi/public/v1.json.

The full schema used by Citadel's web UI is internal and is not the external contract. Read the release notes before upgrading an integration.

Loading API reference…