API reference
All JSON routes live under /api/v1/. The OpenAPI document is served at
/api/v1/openapi.json; generate a client from it with any OpenAPI tool.
Authentication
| Caller | Send |
|---|---|
| Your backend | Authorization: Bearer mtbl_… (an API key) |
| The console | the session cookie (set by sign-in) |
| The CLI | its access token from mountable login |
What an API key may do is listed under Permissions.
Most used routes
| Method and path | Does |
|---|---|
POST /api/v1/mount-sessions | create a mount session; returns a one-time ticket |
DELETE /api/v1/mount-sessions/{session_id} | revoke a session |
GET /api/v1/me | who is calling; for an API key, its api_key: {id, org_id} |
GET /api/v1/orgs/{org_id}/filesystems | list filesystems (a key sees those it has a grant on) |
POST /api/v1/orgs/{org_id}/filesystems | create a filesystem |
PUT /api/v1/orgs/{org_id}/filesystems/{fs_id}/grants | set a grant |
Errors
Errors carry a stable code: {"detail": {"code": "no_grant"}}. Validation
errors return 422 with a list of field problems.