Choose a category#
Authentication4 routesChat & saved commands20 routesFiles5 routesTables & presentation4 routesUsers & identity11 routesRoles & permissions4 routesModules & diagnostics11 routesMCP connections15 routesApprovals5 routesSettings & personal AI9 routesCodex5 routesCommercial status & first run2 routesUpdate contractsContract notesDiagnostics1 routesAudit2 routesPages & certificates10 routes
Shared security boundary#
This reference describes the YAADMIN application, not services running on yaadmin.io. Use paths against your own installation. Cookie sessions, CSRF, administrator-role and owner/tool checks are documented per category and in API overview.
Evidence scope#
Routes are verified in source. Some credential definitions are redacted; handler-local error codes do not describe every downstream failure. Framework API docs are separate from the explicit handler count. Update paths are outbound contracts, with no verified update execution route.