Home / API / Chat & saved commands API
Application boundary# These paths belong to your YAADMIN installation. They are not callable product-website APIs. Authenticated mutations require a session-matched X-CSRF-Token unless the route is public. Handler-local error codes are not exhaustive downstream schemas.
Verified routes#
GET /chat⌄ Chat page.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure HTML template response (handler names the template)Important errors none literal; shared/helper errors apply Approval behavior no standalone approval behavior in this handler. Verified route registration · handler chat_page. Some definitions may be partially redacted; no missing fields are inferred.
GET /api/chat/activity⌄ Chat activity.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure JSONResponse({'events': list(entry.activity_events), 'active': len(entry.activity_active), 'cancellable': _entry_has_cancellable_tasks(entry), 'server_time': int(time.timImportant errors none literal; shared/helper errors apply Approval behavior no standalone approval behavior in this handler. Verified route registration · handler api_chat_activity. Some definitions may be partially redacted; no missing fields are inferred.
GET /api/chat/activity/stream⌄ Chat activity stream.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure StreamingResponse(stream(), media_type='text/event-stream', headers={'Cache-Control': 'private, no-cache, no-store', 'X-Accel-Buffering': 'no', 'X-Content-Type-Options': Important errors none literal; shared/helper errors apply Approval behavior no standalone approval behavior in this handler. Verified route registration · handler api_chat_activity_stream. Some definitions may be partially redacted; no missing fields are inferred.
GET /api/chat/history⌄ Chat history.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {session_id, conversation_id, title, messages, approvals}Important errors none literal; shared/helper errors apply Approval behavior no standalone approval behavior in this handler. Verified route registration · handler api_chat_history. Some definitions may be partially redacted; no missing fields are inferred.
GET /api/chat/conversations⌄ Chat conversations.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters q="", limit=50 Headers none beyond shared session/CSRF Response structure {items, folders, query, current_conversation_id}Important errors none literal; shared/helper errors apply Approval behavior no standalone approval behavior in this handler. Verified route registration · handler api_chat_conversations. Some definitions may be partially redacted; no missing fields are inferred.
POST /api/chat/folders⌄ Chat folder create.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body ChatFolderCreatePayload [name] Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {ok, folder}Important errors 409 Approval behavior no standalone approval behavior in this handler. Request fields Verified route registration · handler api_chat_folder_create. Some definitions may be partially redacted; no missing fields are inferred.
DELETE /api/chat/folders/{folder_id}⌄ Chat folder delete.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {ok, deleted}Important errors 404 Approval behavior no standalone approval behavior in this handler. Verified route registration · handler api_chat_folder_delete. Some definitions may be partially redacted; no missing fields are inferred.
PATCH /api/chat/conversations/{conversation_id}/folder⌄ Chat conversation folder.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body ChatFolderAssignPayload [folder_id] Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {ok, conversation_id, folder_id}Important errors 404 Approval behavior no standalone approval behavior in this handler. Request fields Verified route registration · handler api_chat_conversation_folder. Some definitions may be partially redacted; no missing fields are inferred.
GET /api/quick-commands⌄ Quick commands.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters q="", limit=100 Headers none beyond shared session/CSRF Response structure {items, folders, query}Important errors none literal; shared/helper errors apply Approval behavior no standalone approval behavior in this handler. Verified route registration · handler api_quick_commands. Some definitions may be partially redacted; no missing fields are inferred.
POST /api/quick-commands⌄ Quick command create.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body QuickCommandCreatePayload [name, prompt, run_mode, folder_id] Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {ok, item}Important errors 400, 404 Approval behavior no standalone approval behavior in this handler. Request fields Verified route registration · handler api_quick_command_create. Some definitions may be partially redacted; no missing fields are inferred.
PATCH /api/quick-commands/{command_id}⌄ Quick command update.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body QuickCommandUpdatePayload [name, prompt, run_mode] Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {ok, item}Important errors 400, 404 Approval behavior no standalone approval behavior in this handler. Request fields Verified route registration · handler api_quick_command_update. Some definitions may be partially redacted; no missing fields are inferred.
DELETE /api/quick-commands/{command_id}⌄ Quick command delete.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {ok, deleted}Important errors 404 Approval behavior no standalone approval behavior in this handler. Verified route registration · handler api_quick_command_delete. Some definitions may be partially redacted; no missing fields are inferred.
PATCH /api/quick-commands/{command_id}/folder⌄ Quick command folder.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body QuickCommandFolderAssignPayload [folder_id] Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {ok, command_id, folder_id}Important errors 404 Approval behavior no standalone approval behavior in this handler. Request fields Verified route registration · handler api_quick_command_folder. Some definitions may be partially redacted; no missing fields are inferred.
POST /api/quick-command-folders⌄ Quick command folder create.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body QuickCommandFolderCreatePayload [name] Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {ok, folder}Important errors 409 Approval behavior no standalone approval behavior in this handler. Request fields Verified route registration · handler api_quick_command_folder_create. Some definitions may be partially redacted; no missing fields are inferred.
DELETE /api/quick-command-folders/{folder_id}⌄ Quick command folder delete.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {ok, deleted}Important errors 404 Approval behavior no standalone approval behavior in this handler. Verified route registration · handler api_quick_command_folder_delete. Some definitions may be partially redacted; no missing fields are inferred.
DELETE /api/chat/conversations/{conversation_id}⌄ Chat conversation delete.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {ok, deleted, current_conversation_id}Important errors 404, 409 Approval behavior no standalone approval behavior in this handler. Verified route registration · handler api_chat_conversation_delete. Some definitions may be partially redacted; no missing fields are inferred.
POST /api/chat/conversations/{conversation_id}/open⌄ Chat conversation open.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {ok, conversation_id, title, messages, approvals}Important errors 404, 409 Approval behavior no standalone approval behavior in this handler. Verified route registration · handler api_chat_conversation_open. Some definitions may be partially redacted; no missing fields are inferred.
POST /api/chat/cancel⌄ Chat cancel.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {ok, cancelled, cancelled_count, warning}Important errors none literal; shared/helper errors apply Approval behavior no standalone approval behavior in this handler. Verified route registration · handler api_chat_cancel. Some definitions may be partially redacted; no missing fields are inferred.
POST /api/chat⌄ Chat.
Authentication session Permission files.read, codex.use (special default-allow fallback for assigned role; see §6) Request body ChatPayload [message, attachment_ids] Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {cancelled, answer, generated_files, tool_calls_executed, session_id, conversation_id, approvals, attachments, file_content_parsing, attachment_context, warning}; {answer, ai_mode, generated_files, tool_calls_executed, session_id, conversation_id, approvals, attachments, file_content_parsing, attachment_context}Important errors 403, 404, 409, 500, 503 Approval behavior runtime tool policies/RBAC may produce pending approval cards. Request fields Verified route registration · handler api_chat. Some definitions may be partially redacted; no missing fields are inferred.
POST /api/chat/reset⌄ Chat reset.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {ok, reset, conversation_id}Important errors 409 Approval behavior no standalone approval behavior in this handler. Verified route registration · handler api_chat_reset. Some definitions may be partially redacted; no missing fields are inferred.
Implementation reference: 2026-10-02. Labels distinguish verified behavior, partial implementation and architectural intent.