Home / API / Pages & certificates API
Application boundary# These paths belong to your YAADMIN installation. They are not callable product-website APIs. Authenticated mutations require a session-matched X-CSRF-Token unless the route is public. Handler-local error codes are not exhaustive downstream schemas.
Verified routes#
GET /certificate⌄ Certificate page.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure RedirectResponse(url='/help/certificates', status_code=303)Important errors 303 Approval behavior no standalone approval behavior in this handler. Verified route registration · handler certificate_page. Some definitions may be partially redacted; no missing fields are inferred.
GET /certificate/download⌄ Certificate download.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure FileResponse(path=certificate_path, media_type='application/pkix-cert', filename='YAADMIN-Local-CA.cer', headers={'Cache-Control': 'no-store'})Important errors 404 Approval behavior no standalone approval behavior in this handler. Verified route registration · handler certificate_download. Some definitions may be partially redacted; no missing fields are inferred.
GET /⌄ Dashboard.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure HTML template response (handler names the template)Important errors none literal; shared/helper errors apply Approval behavior no standalone approval behavior in this handler. Verified route registration · handler dashboard. Some definitions may be partially redacted; no missing fields are inferred.
GET /help⌄ Help page.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure HTML template response (handler names the template)Important errors none literal; shared/helper errors apply Approval behavior no standalone approval behavior in this handler. Verified route registration · handler help_page. Some definitions may be partially redacted; no missing fields are inferred.
GET /help/certificates⌄ Help certificates page.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure HTML template response (handler names the template)Important errors none literal; shared/helper errors apply Approval behavior no standalone approval behavior in this handler. Verified route registration · handler help_certificates_page. Some definitions may be partially redacted; no missing fields are inferred.
GET /help/api⌄ Help page.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure HTML template response (handler names the template)Important errors none literal; shared/helper errors apply Approval behavior no standalone approval behavior in this handler. Verified route registration · handler help_api_page. Some definitions may be partially redacted; no missing fields are inferred.
GET /help/about⌄ Help about page.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure HTML template response (handler names the template)Important errors none literal; shared/helper errors apply Approval behavior no standalone approval behavior in this handler. Verified route registration · handler help_about_page. Some definitions may be partially redacted; no missing fields are inferred.
GET /help/author⌄ Help author page.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure HTML template response (handler names the template)Important errors none literal; shared/helper errors apply Approval behavior no standalone approval behavior in this handler. Verified route registration · handler help_author_page. Some definitions may be partially redacted; no missing fields are inferred.
GET /api/ui-preferences⌄ Ui preferences.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {language, personal_prompt, supported_languages}Important errors none literal; shared/helper errors apply Approval behavior no standalone approval behavior in this handler. Verified route registration · handler api_ui_preferences. Some definitions may be partially redacted; no missing fields are inferred.
PATCH /api/ui-preferences⌄ Ui preferences update.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body UiPreferencesPayload [language, personal_prompt] Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {ok, language, personal_prompt}Important errors 400 Approval behavior no standalone approval behavior in this handler. Request fields Verified route registration · handler api_ui_preferences_update. Some definitions may be partially redacted; no missing fields are inferred.
Implementation reference: 2026-10-02. Labels distinguish verified behavior, partial implementation and architectural intent.