Skip to content

Overview

Gateway is an infrastructure control plane for managing nodes, reverse proxies, Docker workloads, certificates, databases, logging, monitoring, status pages, notifications, and operational automation.

Authentication

Browser sessions authenticate through the HttpOnly session_id cookie set by OIDC login. Cookie-authenticated mutating requests must include X-CSRF-Token from /auth/csrf.

API tokens use Authorization: Bearer gw_... for programmatic REST access. OAuth public clients use Authorization Code + PKCE and Gateway-issued gwo_... access tokens for the same programmatic API surface.

Remote MCP

POST /api/mcp exposes Gateway through stateless Streamable HTTP MCP. It accepts only OAuth gwo_... access tokens issued for the Gateway MCP resource. Browser cookies, gw_... API tokens, and gwl_... logging ingest tokens are not accepted.

Public PKI Endpoints

CRL and OCSP endpoints under /pki/ are unauthenticated and publicly accessible.

Information

  • OpenAPI version: 3.1.0
Authentication18 operationsUser authentication via OIDCCertificate Authorities9 operationsCA creation and managementCertificates7 operationsCertificate issuance, revocation, and exportTemplates5 operationsCertificate template managementPKI4 operationsPublic PKI endpoints (CRL, OCSP)Audit12 operationsAudit logAlerts2 operationsExpiry alerts and notificationsTokens4 operationsAPI token managementAdmin24 operationsUser administrationNodes33 operationsGateway node enrollment, configuration, and monitoringRoutes18 operationsIngress route management; stable API paths retain the proxy-hosts nameRoute Folders10 operationsIngress route folder organizationNginx Templates8 operationsReusable nginx config templatesDocker Containers24 operationsDocker container lifecycle and inspectionDocker Deployments20 operationsBlue/green Docker deploymentsDocker Images5 operationsDocker image pull, remove, and prune operationsDocker Volumes22 operationsDocker volume managementDocker Networks5 operationsDocker network managementDocker Registries10 operationsPrivate Docker registry credentialsDocker Folders10 operationsDocker container folder organizationDocker Health Checks6 operationsGateway-managed Docker health checksDocker Migrations6 operationsDurable Docker node-to-node migrationsDocker Secrets8 operationsContainer and deployment environment secretsDocker Files11 operationsContainer file browser operationsDocker Tasks3 operationsDocker background tasksDocker Webhooks5 operationsExternal Docker update webhooksSSL Certificates19 operationsSSL/TLS certificate managementDomains21 operationsDomain inventory and DNS checksAccess Lists5 operationsIP and basic-auth access controlsDatabases64 operationsDatabase connections, monitoring, and explorersStatus Page17 operationsStatus page settings, services, and incidentsLogging21 operationsLog ingestion, schemas, tokens, search, and metadataAI4 operationsAI assistant configuration and metadataInference9 operationsStandalone multi-provider inference proxy managementSystem10 operationsVersion, release, and update operationsLicense4 operationsGateway license activation and statusHousekeeping5 operationsRetention, cleanup, and housekeeping runsMonitoring4 operationsDashboard, health, log, and nginx monitoringNotifications17 operationsNotification webhooks and alert rulesInference Providers11 operationsInference Models6 operationsInference Usage6 operationsInference Limits6 operationsAdmin Folders16 operationsDocker Nodes3 operationsDocker Image Cleanup2 operationsDocker Compose16 operationsDocker Builds2 operationsResources1 operationsPages33 operationsPages Deploy API3 operationsSettings2 operationsIntegrations27 operationsLogging Folders16 operations

Gateway API token (gw_...) or OAuth access token (gwo_...) for programmatic access. Browser sessions use the HttpOnly session cookie.

Security scheme type: http

Dedicated Gateway inference token (gwi_...). Valid only on inference adapter data planes.

Security scheme type: http