Home / API / Tables & presentation API
Application boundary# These paths belong to your YAADMIN installation. They are not callable product-website APIs. Authenticated mutations require a session-matched X-CSRF-Token unless the route is public. Handler-local error codes are not exhaustive downstream schemas.
Verified routes#
GET /api/files/{file_id}/preview⌄ Image preview.
Authentication session Permission files.read Request body none Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure FileResponse(path, media_type=media[record.extension], headers={'Cache-Control': 'private, no-store', 'X-Content-Type-Options': 'nosniff', 'Content-Disposition': "inline;Important errors 403, 409 Approval behavior file HTTP permissions requiring approval fail 409; no one-time approval implementation. Verified route registration · handler image_preview. Some definitions may be partially redacted; no missing fields are inferred.
GET /api/files/{file_id}/table⌄ File table.
Authentication session Permission files.read Request body none Query parameters page=1, page_size=25, view='{}', sheet='' Headers none beyond shared session/CSRF Response structure JSONResponse(result, headers={'Cache-Control': 'private, no-store'})Important errors 403, 409 Approval behavior file HTTP permissions requiring approval fail 409; no one-time approval implementation. Verified route registration · handler file_table. Some definitions may be partially redacted; no missing fields are inferred.
POST /api/chat/tables/export⌄ Export table.
Authentication session Permission files.create, files.read Request body raw request body; JSON keys: ai_column_presentation, columns, file_id, rows, sheet, title, view Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure Response(data, media_type=XLSX_MIME, headers={'Cache-Control': 'private, no-store', 'X-Content-Type-Options': 'nosniff', 'Content-Disposition': "attachment; filename*=UTFImportant errors 403, 409, 413 Approval behavior file HTTP permissions requiring approval fail 409; no one-time approval implementation. Verified route registration · handler export_table. Some definitions may be partially redacted; no missing fields are inferred.
POST /api/chat/table-labels⌄ Ai table labels.
Authentication session Permission no separate permission identifier in handler (admin/owner/runtime checks as above) Request body ColumnRequest [keys, title, question] Query parameters none explicitly read Headers none beyond shared session/CSRF Response structure {columns, ai_generated}Important errors 400, 503 Approval behavior no standalone approval behavior in this handler. Request fields Verified route registration · handler ai_table_labels. Some definitions may be partially redacted; no missing fields are inferred.
Implementation reference: 2026-10-02. Labels distinguish verified behavior, partial implementation and architectural intent.