Skip to content

Overview

Gateway is an infrastructure control plane for managing nodes, reverse proxies, Docker workloads, certificates, databases, logging, monitoring, status pages, notifications, and operational automation.

Authentication

Browser sessions authenticate through the HttpOnly session_id cookie set by OIDC login. Cookie-authenticated mutating requests must include X-CSRF-Token from /auth/csrf.

API tokens use Authorization: Bearer gw_... for programmatic REST access. OAuth public clients use Authorization Code + PKCE and Gateway-issued gwo_... access tokens for the same programmatic API surface.

Remote MCP

POST /api/mcp exposes Gateway through stateless Streamable HTTP MCP. It accepts only OAuth gwo_... access tokens issued for the Gateway MCP resource. Browser cookies, gw_... API tokens, and gwl_... logging ingest tokens are not accepted.

Public PKI Endpoints

CRL and OCSP endpoints under /pki/ are unauthenticated and publicly accessible.

Idempotent retries

Selected create operations accept an optional Idempotency-Key header (1-255 printable ASCII characters, for example a UUID); each lists it as a parameter. They cover containers, deployments, Compose projects, volumes, networks, registries, routes and route folders, domains, ACME certificates, certificate authorities, databases and managed databases, storage connections and managed storage, Page Projects, alert rules, and SIEM destinations. A client that retries after a timeout with the same key gets the original result instead of creating a second resource. Operations that return a secret once (tokens, enrollment, keys, credentials) never take the header.

Keys are bound to the API/OAuth token or browser session, its current effective scopes, the method, and the path; results are kept encrypted for 24 hours, and every replay is audited. After a scope change the key starts fresh.

  • Same key and same request (query and JSON body): the stored response is replayed with Idempotency-Replayed: true.
  • Same key with a different request: 422 IDEMPOTENCY_KEY_REUSED.
  • Same key while the first request is still running: 409 IDEMPOTENCY_KEY_IN_PROGRESS with Retry-After.
  • The first request completed but its response was not stored (it looked secret or was over 1 MiB): 409 IDEMPOTENCY_RESPONSE_WITHHELD with the original status and Location when known; look the resource up instead of retrying.

Only 2xx and deterministic 400, 404, 409, and 422 JSON responses are recorded. 401, 403, 5xx, streamed, and non-JSON responses are not, so a retry runs again. Request bodies over 1 MiB or not JSON run without idempotency, and so do all requests when the idempotency store is unavailable. Remote MCP create tools take an idempotencyKey argument with the same semantics.

Information

  • OpenAPI version: 3.1.0
Authentication19 operationsUser authentication via OIDCCertificate Authorities17 operationsCA creation and managementCertificates15 operationsCertificate issuance, revocation, and exportTemplates13 operationsCertificate template managementPKI4 operationsPublic PKI endpoints (CRL, OCSP)Audit12 operationsAudit logAlerts2 operationsExpiry alerts and notificationsTokens4 operationsAPI token managementAdmin25 operationsUser administrationNodes34 operationsGateway node enrollment, configuration, and monitoringRoutes20 operationsIngress route management; stable API paths retain the proxy-hosts nameRoute Folders10 operationsIngress route folder organizationNginx Templates16 operationsReusable nginx config templatesDocker Containers24 operationsDocker container lifecycle and inspectionDocker Deployments20 operationsBlue/green Docker deploymentsDocker Images5 operationsDocker image pull, remove, and prune operationsDocker Volumes22 operationsDocker volume managementDocker Networks5 operationsDocker network managementDocker Registries10 operationsPrivate Docker registry credentialsDocker Folders10 operationsDocker container folder organizationDocker Health Checks6 operationsGateway-managed Docker health checksDocker Migrations7 operationsDurable Docker node-to-node migrationsDocker Secrets8 operationsContainer and deployment environment secretsDocker Files11 operationsContainer file browser operationsDocker Tasks3 operationsDocker background tasksDocker Webhooks5 operationsExternal Docker update webhooksSSL Certificates19 operationsSSL/TLS certificate managementDomains22 operationsDomain inventory and DNS checksAccess Lists5 operationsIP and basic-auth access controlsDatabases65 operationsDatabase connections, monitoring, and explorersStatus Page18 operationsStatus page settings, services, and incidentsLogging21 operationsLog ingestion, schemas, tokens, search, and metadataAI4 operationsAI assistant configuration and metadataInference9 operationsStandalone multi-provider inference proxy managementSystem13 operationsVersion, release, and update operationsLicense5 operationsGateway license activation and statusHousekeeping5 operationsRetention, cleanup, and housekeeping runsMonitoring4 operationsDashboard, health, log, and nginx monitoringNotifications17 operationsNotification webhooks and alert rulesInference Providers11 operationsInference Models6 operationsInference Usage6 operationsInference Limits6 operationsAdmin Folders16 operationsDocker Nodes3 operationsDocker Image Cleanup2 operationsDocker Compose16 operationsDocker Availability9 operationsDocker Builds6 operationsResources1 operationsIngress groups10 operationsSettings2 operationsIntegrations29 operationsPages36 operationsPages Deploy API4 operationsLogging Folders16 operationsDatabase Backups9 operationsStorage Copy Jobs4 operationsManaged Storage24 operationsObject Storage28 operations

Gateway API token (gw_...) or OAuth access token (gwo_...) for programmatic access. Browser sessions use the HttpOnly session cookie.

Security scheme type: http

Dedicated Gateway inference token (gwi_...). Valid only on inference adapter data planes.

Security scheme type: http