Skip to content
YAADMIN
Download

APPLICATION REFERENCE

Chat & saved commands API

20 verified chat & saved commands routes: authentication, fields, responses, errors and approval boundaries.

VerifiedSource snapshot · 2026-10-02

Application boundary#

These paths belong to your YAADMIN installation. They are not callable product-website APIs. Authenticated mutations require a session-matched X-CSRF-Token unless the route is public. Handler-local error codes are not exhaustive downstream schemas.

Verified routes#

20 routes

GET/chat

Chat page.

Authentication
session
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
none
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
HTML template response (handler names the template)
Important errors
none literal; shared/helper errors apply
Approval behavior
no standalone approval behavior in this handler.

Verified route registration · handler chat_page. Some definitions may be partially redacted; no missing fields are inferred.

GET/api/chat/activity

Chat activity.

Authentication
session
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
none
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
JSONResponse({'events': list(entry.activity_events), 'active': len(entry.activity_active), 'cancellable': _entry_has_cancellable_tasks(entry), 'server_time': int(time.tim
Important errors
none literal; shared/helper errors apply
Approval behavior
no standalone approval behavior in this handler.

Verified route registration · handler api_chat_activity. Some definitions may be partially redacted; no missing fields are inferred.

GET/api/chat/activity/stream

Chat activity stream.

Authentication
session
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
none
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
StreamingResponse(stream(), media_type='text/event-stream', headers={'Cache-Control': 'private, no-cache, no-store', 'X-Accel-Buffering': 'no', 'X-Content-Type-Options':
Important errors
none literal; shared/helper errors apply
Approval behavior
no standalone approval behavior in this handler.

Verified route registration · handler api_chat_activity_stream. Some definitions may be partially redacted; no missing fields are inferred.

GET/api/chat/history

Chat history.

Authentication
session
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
none
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{session_id, conversation_id, title, messages, approvals}
Important errors
none literal; shared/helper errors apply
Approval behavior
no standalone approval behavior in this handler.

Verified route registration · handler api_chat_history. Some definitions may be partially redacted; no missing fields are inferred.

GET/api/chat/conversations

Chat conversations.

Authentication
session
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
none
Query parameters
q="", limit=50
Headers
none beyond shared session/CSRF
Response structure
{items, folders, query, current_conversation_id}
Important errors
none literal; shared/helper errors apply
Approval behavior
no standalone approval behavior in this handler.

Verified route registration · handler api_chat_conversations. Some definitions may be partially redacted; no missing fields are inferred.

POST/api/chat/folders

Chat folder create.

Authentication
session
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
ChatFolderCreatePayload [name]
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{ok, folder}
Important errors
409
Approval behavior
no standalone approval behavior in this handler.

Request fields

FieldVerified definition
namestr = Field(min_length=1, max_length=80)

Verified route registration · handler api_chat_folder_create. Some definitions may be partially redacted; no missing fields are inferred.

DELETE/api/chat/folders/{folder_id}

Chat folder delete.

Authentication
session
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
none
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{ok, deleted}
Important errors
404
Approval behavior
no standalone approval behavior in this handler.

Verified route registration · handler api_chat_folder_delete. Some definitions may be partially redacted; no missing fields are inferred.

PATCH/api/chat/conversations/{conversation_id}/folder

Chat conversation folder.

Authentication
session
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
ChatFolderAssignPayload [folder_id]
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{ok, conversation_id, folder_id}
Important errors
404
Approval behavior
no standalone approval behavior in this handler.

Request fields

FieldVerified definition
folder_idstr | None = Field(default=None, max_length=64)

Verified route registration · handler api_chat_conversation_folder. Some definitions may be partially redacted; no missing fields are inferred.

GET/api/quick-commands

Quick commands.

Authentication
session
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
none
Query parameters
q="", limit=100
Headers
none beyond shared session/CSRF
Response structure
{items, folders, query}
Important errors
none literal; shared/helper errors apply
Approval behavior
no standalone approval behavior in this handler.

Verified route registration · handler api_quick_commands. Some definitions may be partially redacted; no missing fields are inferred.

POST/api/quick-commands

Quick command create.

Authentication
session
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
QuickCommandCreatePayload [name, prompt, run_mode, folder_id]
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{ok, item}
Important errors
400, 404
Approval behavior
no standalone approval behavior in this handler.

Request fields

FieldVerified definition
namestr = Field(min_length=1, max_length=100)
promptstr = Field(min_length=1, max_length=20_000)
run_modestr = Field(default="new_chat", max_length=32)
folder_idstr | None = Field(default=None, max_length=64)

Verified route registration · handler api_quick_command_create. Some definitions may be partially redacted; no missing fields are inferred.

PATCH/api/quick-commands/{command_id}

Quick command update.

Authentication
session
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
QuickCommandUpdatePayload [name, prompt, run_mode]
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{ok, item}
Important errors
400, 404
Approval behavior
no standalone approval behavior in this handler.

Request fields

FieldVerified definition
namestr = Field(min_length=1, max_length=100)
promptstr = Field(min_length=1, max_length=20_000)
run_modestr = Field(default="new_chat", max_length=32)

Verified route registration · handler api_quick_command_update. Some definitions may be partially redacted; no missing fields are inferred.

DELETE/api/quick-commands/{command_id}

Quick command delete.

Authentication
session
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
none
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{ok, deleted}
Important errors
404
Approval behavior
no standalone approval behavior in this handler.

Verified route registration · handler api_quick_command_delete. Some definitions may be partially redacted; no missing fields are inferred.

PATCH/api/quick-commands/{command_id}/folder

Quick command folder.

Authentication
session
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
QuickCommandFolderAssignPayload [folder_id]
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{ok, command_id, folder_id}
Important errors
404
Approval behavior
no standalone approval behavior in this handler.

Request fields

FieldVerified definition
folder_idstr | None = Field(default=None, max_length=64)

Verified route registration · handler api_quick_command_folder. Some definitions may be partially redacted; no missing fields are inferred.

POST/api/quick-command-folders

Quick command folder create.

Authentication
session
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
QuickCommandFolderCreatePayload [name]
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{ok, folder}
Important errors
409
Approval behavior
no standalone approval behavior in this handler.

Request fields

FieldVerified definition
namestr = Field(min_length=1, max_length=80)

Verified route registration · handler api_quick_command_folder_create. Some definitions may be partially redacted; no missing fields are inferred.

DELETE/api/quick-command-folders/{folder_id}

Quick command folder delete.

Authentication
session
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
none
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{ok, deleted}
Important errors
404
Approval behavior
no standalone approval behavior in this handler.

Verified route registration · handler api_quick_command_folder_delete. Some definitions may be partially redacted; no missing fields are inferred.

DELETE/api/chat/conversations/{conversation_id}

Chat conversation delete.

Authentication
session
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
none
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{ok, deleted, current_conversation_id}
Important errors
404, 409
Approval behavior
no standalone approval behavior in this handler.

Verified route registration · handler api_chat_conversation_delete. Some definitions may be partially redacted; no missing fields are inferred.

POST/api/chat/conversations/{conversation_id}/open

Chat conversation open.

Authentication
session
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
none
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{ok, conversation_id, title, messages, approvals}
Important errors
404, 409
Approval behavior
no standalone approval behavior in this handler.

Verified route registration · handler api_chat_conversation_open. Some definitions may be partially redacted; no missing fields are inferred.

POST/api/chat/cancel

Chat cancel.

Authentication
session
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
none
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{ok, cancelled, cancelled_count, warning}
Important errors
none literal; shared/helper errors apply
Approval behavior
no standalone approval behavior in this handler.

Verified route registration · handler api_chat_cancel. Some definitions may be partially redacted; no missing fields are inferred.

POST/api/chat

Chat.

Authentication
session
Permission
files.read, codex.use (special default-allow fallback for assigned role; see §6)
Request body
ChatPayload [message, attachment_ids]
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{cancelled, answer, generated_files, tool_calls_executed, session_id, conversation_id, approvals, attachments, file_content_parsing, attachment_context, warning}; {answer, ai_mode, generated_files, tool_calls_executed, session_id, conversation_id, approvals, attachments, file_content_parsing, attachment_context}
Important errors
403, 404, 409, 500, 503
Approval behavior
runtime tool policies/RBAC may produce pending approval cards.

Request fields

FieldVerified definition
messagestr = Field(min_length=1, max_length=20_000)
attachment_idslist[str] = Field(default_factory=list, max_length=20)

Verified route registration · handler api_chat. Some definitions may be partially redacted; no missing fields are inferred.

POST/api/chat/reset

Chat reset.

Authentication
session
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
none
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{ok, reset, conversation_id}
Important errors
409
Approval behavior
no standalone approval behavior in this handler.

Verified route registration · handler api_chat_reset. Some definitions may be partially redacted; no missing fields are inferred.

Implementation reference: 2026-10-02. Labels distinguish verified behavior, partial implementation and architectural intent.

Search documentation

Search stays in your browser.