Information
- OpenAPI version:
3.1.0
Gateway is an infrastructure control plane for managing nodes, reverse proxies, Docker workloads, certificates, databases, logging, monitoring, status pages, notifications, and operational automation.
Browser sessions authenticate through the HttpOnly session_id cookie set by OIDC login. Cookie-authenticated mutating requests must include X-CSRF-Token from /auth/csrf.
API tokens use Authorization: Bearer gw_... for programmatic REST access. OAuth public clients use Authorization Code + PKCE and Gateway-issued gwo_... access tokens for the same programmatic API surface.
POST /api/mcp exposes Gateway through stateless Streamable HTTP MCP. It accepts only OAuth gwo_... access tokens issued for the Gateway MCP resource. Browser cookies, gw_... API tokens, and gwl_... logging ingest tokens are not accepted.
CRL and OCSP endpoints under /pki/ are unauthenticated and publicly accessible.
Selected create operations accept an optional Idempotency-Key header (1-255 printable ASCII characters, for example a UUID); each lists it as a parameter. They cover containers, deployments, Compose projects, volumes, networks, registries, routes and route folders, domains, ACME certificates, certificate authorities, databases and managed databases, storage connections and managed storage, Page Projects, alert rules, and SIEM destinations. A client that retries after a timeout with the same key gets the original result instead of creating a second resource. Operations that return a secret once (tokens, enrollment, keys, credentials) never take the header.
Keys are bound to the API/OAuth token or browser session, its current effective scopes, the method, and the path; results are kept encrypted for 24 hours, and every replay is audited. After a scope change the key starts fresh.
Idempotency-Replayed: true.422 IDEMPOTENCY_KEY_REUSED.409 IDEMPOTENCY_KEY_IN_PROGRESS with Retry-After.409 IDEMPOTENCY_RESPONSE_WITHHELD with the original status and Location when known; look the resource up instead of retrying.Only 2xx and deterministic 400, 404, 409, and 422 JSON responses are recorded. 401, 403, 5xx, streamed, and non-JSON responses are not, so a retry runs again. Request bodies over 1 MiB or not JSON run without idempotency, and so do all requests when the idempotency store is unavailable. Remote MCP create tools take an idempotencyKey argument with the same semantics.
Gateway API token (gw_...) or OAuth access token (gwo_...) for programmatic access. Browser sessions use the HttpOnly session cookie.
Security scheme type: http
Dedicated Gateway inference token (gwi_...). Valid only on inference adapter data planes.
Security scheme type: http