Application API, separate from this website#
The catalog describes the YAADMIN application's 108 explicit routes. Paths such as /api/chat belong to your YAADMIN installation. They are not services hosted by this product website.
Browse the categorized API reference.
Authentication and CSRF#
The web API uses the controlhub_auth_session cookie. Public paths are /login, /api/auth/login and /api/health; static assets are public. Other API requests require a valid session; unauthenticated API requests return 401, while pages redirect to login.
Authenticated mutations require X-CSRF-Token matching the session. Login is public and bypasses that check. Administrator routes are guarded by the exact system role rather than invented administrative permission IDs.
Verified request example#
This is the ChatPayload body shape for POST /api/chat on your installation, not a runnable request to yaadmin.io:
{
"message": "List the available endpoint inventory.",
"attachment_ids": []
}message is required with length 1..20000; attachment_ids defaults to an empty list and accepts at most 20 items. Actual tool execution depends on configuration, RBAC and approval.
Categories#
Current implementation notes#
There is no verified standalone scheduler, update-execution, license activation or email-registration route. Remote update URLs are client contracts, not evidence of deployed website endpoints.