• English
  • Octop REST and WebSocket API: Endpoints and Access Guide

    Octop exposes every feature through an HTTP and WebSocket API at /api. Most endpoints need a JWT from POST /api/auth/login. Responses are JSON unless the endpoint streams events or returns a file.

    Base URL

    http://127.0.0.1:8088/api

    Replace the host and port if you run Octop somewhere else.

    Get a token

    Post your username and password to POST /api/auth/login, then send the token on later requests:

    Authorization: Bearer <access_token>

    The chat WebSocket takes the same token as ?token=<access_token>. You can also sign in with OIDC, Feishu / DingTalk / WeCom OAuth, or an invite link — see Authentication.

    Interactive API docs

    Octop ships the Scalar interface for trying endpoints in the browser. It is off by default.

    Enable it

    Set "enable_api_docs": true in ~/.octop/config.json, or set OCTOP_ENABLE_API_DOCS=1.

    Restart Octop

    Restart octop run.

    Open the docs

    Visit http://127.0.0.1:8088/api/docs. The raw schema is always at /api/openapi.json.

    Who can call what

    LevelMeaning
    publicNo token required (health, login, first-run setup, OAuth callbacks)
    userAny signed-in account
    ownerThe person who owns the resource, or an administrator
    adminAdministrator only

    Administrators can do everything. Regular users only get extra settings access if you grant it.

    Check that the server is up

    curl http://127.0.0.1:8088/api/health
    # {"status": "ok", "version": "1.0.1"}

    Login attempts are rate-limited (default 5 tries, then a 15-minute lockout). An administrator can unlock an account from Management → Users.

    Explore the API