Information
- OpenAPI version:
3.1.0
Gateway is an infrastructure control plane for managing nodes, reverse proxies, Docker workloads, certificates, databases, logging, monitoring, status pages, notifications, and operational automation.
Browser sessions authenticate through the HttpOnly session_id cookie set by OIDC login. Cookie-authenticated mutating requests must include X-CSRF-Token from /auth/csrf.
API tokens use Authorization: Bearer gw_... for programmatic REST access. OAuth public clients use Authorization Code + PKCE and Gateway-issued gwo_... access tokens for the same programmatic API surface.
POST /api/mcp exposes Gateway through stateless Streamable HTTP MCP. It accepts only OAuth gwo_... access tokens issued for the Gateway MCP resource. Browser cookies, gw_... API tokens, and gwl_... logging ingest tokens are not accepted.
CRL and OCSP endpoints under /pki/ are unauthenticated and publicly accessible.
Gateway API token (gw_...) or OAuth access token (gwo_...) for programmatic access. Browser sessions use the HttpOnly session cookie.
Security scheme type: http
Dedicated Gateway inference token (gwi_...). Valid only on inference adapter data planes.
Security scheme type: http