Home / API / Modules & diagnostics API
Application boundary# These paths belong to your YAADMIN installation. They are not callable product-website APIs. Authenticated mutations require a session-matched X-CSRF-Token unless the route is public. Handler-local error codes are not exhaustive downstream schemas.
Verified routes#
GET /modules⌄ Modules page.
Authentication session + administrator role Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure HTML template response (handler names the template)Important errors none literal; shared/helper errors apply Approval behavior no standalone approval behavior in this handler. Verified route registration · handler modules_page. Some definitions may be partially redacted; no missing fields are inferred.
GET /modules/{module_name}⌄ Module detail page.
Authentication session + administrator role Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure HTML template response (handler names the template)Important errors none literal; shared/helper errors apply Approval behavior no standalone approval behavior in this handler. Verified route registration · handler module_detail_page. Some definitions may be partially redacted; no missing fields are inferred.
PUT /api/modules/{module_name}/settings⌄ Update module settings.
Authentication session + administrator role Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body ModuleSettingsPayload [values, clear_fields] Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {ok, settings, restart_required}Important errors none literal; shared/helper errors apply Approval behavior no standalone approval behavior in this handler. Request fields Verified route registration · handler api_update_module_settings. Some definitions may be partially redacted; no missing fields are inferred.
POST /api/modules/{module_name}/health⌄ Module health.
Authentication session + administrator role Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {ok, health}Important errors none literal; shared/helper errors apply Approval behavior no standalone approval behavior in this handler. Verified route registration · handler api_module_health. Some definitions may be partially redacted; no missing fields are inferred.
GET /api/modules/{module_name}/diagnostics⌄ Module diagnostics.
Authentication session + administrator role Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {ok, module}Important errors none literal; shared/helper errors apply Approval behavior no standalone approval behavior in this handler. Verified route registration · handler api_module_diagnostics. Some definitions may be partially redacted; no missing fields are inferred.
POST /api/modules/{module_name}/enable⌄ Enable module.
Authentication session + administrator role Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {ok, module, catalog}Important errors 503 Approval behavior no standalone approval behavior in this handler. Verified route registration · handler api_enable_module. Some definitions may be partially redacted; no missing fields are inferred.
POST /api/modules/{module_name}/disable⌄ Disable module.
Authentication session + administrator role Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {ok, module, catalog}Important errors 503 Approval behavior no standalone approval behavior in this handler. Verified route registration · handler api_disable_module. Some definitions may be partially redacted; no missing fields are inferred.
GET /api/modules/sdk-ai⌄ Download module ai sdk.
Authentication session + administrator role Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure StreamingResponse(iter((payload,)), media_type='application/zip', headers={'Content-Disposition': 'attachment; filename="YAADMIN-Module-AI-SDK-v1.zip"', 'Content-Length':Important errors 404 Approval behavior no standalone approval behavior in this handler. Verified route registration · handler api_download_module_ai_sdk. Some definitions may be partially redacted; no missing fields are inferred.
POST /api/modules/install⌄ Install module.
Authentication session + administrator role Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body raw request body Query parameters none explicitly read Headers x-module-filename Response structure {ok, **result}Important errors 400, 409, 413 Approval behavior no standalone approval behavior in this handler. Verified route registration · handler api_install_module. Some definitions may be partially redacted; no missing fields are inferred.
POST /api/modules/{module_name}/uninstall-builtin⌄ Uninstall builtin module.
Authentication session + administrator role Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {ok, id, backup, restart_required}Important errors 404, 409, 503 Approval behavior no standalone approval behavior in this handler. Verified route registration · handler api_uninstall_builtin_module. Some definitions may be partially redacted; no missing fields are inferred.
POST /api/modules/{module_name}/uninstall⌄ Uninstall module.
Authentication session + administrator role Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {ok, **result}Important errors 409 Approval behavior no standalone approval behavior in this handler. Verified route registration · handler api_uninstall_module. Some definitions may be partially redacted; no missing fields are inferred.
Implementation reference: 2026-10-02. Labels distinguish verified behavior, partial implementation and architectural intent.