Management REST API
Everything the dashboard does is available over HTTPS on port 8080.
All routes are under /api/v1
The base path is /api/v1. A request to /api/… without the version segment returns 404.
Authenticating
Log in with the admin credentials to get a bearer token, then send it on every subsequent request.
curl -sk -X POST https://your-host:8080/api/v1/auth/login \
-H 'Content-Type: application/json' \
-d '{"username":"admin","password":"$MGMT_ADMIN_PASSWORD"}'The control plane uses a self-signed certificate by default, which is why these examples pass -k. Provide TLS_CERT_FILE and TLS_KEY_FILE for a real certificate.
Endpoints
| Method | Path | Description |
|---|---|---|
POST | /api/v1/auth/login | Exchange admin credentials for a bearer token |
GET | /api/v1/peers | List every peer on the account |
PUT | /api/v1/peers/:key | Rename a peer, or replace its groups |
DELETE | /api/v1/peers/:key | Remove a peer and revoke its token |
PUT | /api/v1/peers/:key/routes | Set the CIDRs a peer advertises to the mesh |
PUT | /api/v1/peers/:key/exit-node | Choose which exit node this peer uses, or clear it |
GET | /api/v1/groups | List groups |
POST | /api/v1/groups | Create a group |
DELETE | /api/v1/groups/:id | Delete a group |
GET | /api/v1/rules | List ACL rules |
POST | /api/v1/rules | Create an ACL rule |
DELETE | /api/v1/rules/:id | Delete an ACL rule |
GET | /api/v1/setup-keys | List enrollment keys |
POST | /api/v1/setup-keys | Create an enrollment key |
DELETE | /api/v1/setup-keys/:id | Revoke an enrollment key |
GET | /api/v1/health | Liveness probe (unauthenticated) |
:key is a peer’s WireGuard public key, URL-encoded.
Examples
Advertise a LAN from a peer so the rest of the mesh can reach it:
curl -sk -X PUT https://your-host:8080/api/v1/peers/$KEY/routes \
-H "Authorization: Bearer $TOKEN" \
-H 'Content-Type: application/json' \
-d '{"routes":["192.168.1.0/24"]}'Point one device at an exit node, without affecting any other peer:
curl -sk -X PUT https://your-host:8080/api/v1/peers/$KEY/exit-node \
-H "Authorization: Bearer $TOKEN" \
-H 'Content-Type: application/json' \
-d '{"exit_node":"<gateway public key>"}'Send {"exit_node":""} to stop using one.