Skip to content
Docs for Flare v2.1.0Latest stable · 10d28125Build details ↗Versions & changes
View docs

Endpoint inventory ​

Flare's dashboard also talks to HTTP routes. Their existence does not make all of them part of the named-token API. This inventory distinguishes the supported automation surface from session-based account/admin actions and public content routes.

Use the OpenAPI document for custom clients using flr_… tokens. It describes the 12 supported method/path combinations across seven paths. The rest of this page is a map for operators and contributors, not a promise of a general administrator REST API.

Paths use {id} for a dynamic segment. {path} and {nextauth} are catch-all path segments. Methods listed here are the implemented handlers; do not assume another method is supported because the path exists.

Named-token API ​

All of these routes also use Flare's shared account authentication helper. A named token must have the specific scope, and results are limited to its owner's account.

PathMethodScopePurpose
/api/filesGETfiles:readPaginated file metadata, search, filters, and image neighbors.
/api/filesPOSTfiles:uploadOne multipart file upload.
/api/files/typesGETfiles:readMIME types present in the account.
/api/files/chunksPOSTfiles:uploadInitialize a chunk upload.
/api/files/chunksGETfiles:uploadObtain a part URL using uploadId and partNumber query parameters.
/api/files/chunksPUTfiles:uploadComplete an upload, returning a data wrapper.
/api/files/chunks/{uploadId}/part/{partNumber}GETfiles:uploadObtain a part upload URL.
/api/files/chunks/{uploadId}/part/{partNumber}PUTfiles:uploadUpload raw part bytes through Flare.
/api/files/chunks/{uploadId}/completePOSTfiles:uploadComplete an upload, returning links without a wrapper.
/api/urlsGETurls:readList the account's short links.
/api/urlsPOSTurls:writeCreate a short link.
/api/urls/{id}DELETEurls:writeDelete an owned short link.

See files, short links, and authentication for request/response details.

File content and access checks ​

These routes check the file's visibility, password, and an optional browser session. They do not use named bearer tokens to grant file access. Public unprotected files can be fetched anonymously. Private files require an owner or administrator session and return 404 to ineligible viewers. A password-protected public file requires its password unless the browser session belongs to its owner or an administrator.

PathMethodsPurpose
/api/files/{path}GETRaw stored content by file URL path; download=true requests attachment handling.
/api/files/{id}/downloadGET, POSTDownload content. GET accepts a password query value; POST accepts password JSON. S3 storage can redirect after access validation.
/api/files/{id}/thumbnailGETServe an image for thumbnail display; currently streams the original image.
/api/files/{id}/ocrGETFetch image OCR text, processing it if necessary, after access validation.

Raw/thumbnail/OCR GET requests accept a password query parameter when applicable. Prefer the normal share-page password flow for people using a browser; URLs containing passwords can be retained in history or logs.

The public-facing route /{userUrlId}/{filename}/raw also enforces file access. /{userUrlId}/{filename}/direct is a video-only lookup that returns JSON containing a signed storage URL or raw-route fallback after checking access; it does not stream the file itself. An issued S3 URL can remain valid until its own expiry after Flare access settings change. /{userUrlId}/{filename} is the rendered share page. GET /u/{shortCode} publicly redirects a short link and increments its count.

Dashboard account routes requiring a browser session ​

These routes explicitly read an interactive session. Neither a named API token nor a legacy account upload token by itself supplies that session. Ownership and feature-policy checks still apply.

PathMethodsPurpose
/api/integrationsGET, POSTList/manage named tokens, webhooks, and deliveries. POST uses action commands and validates same-origin JSON requests.
/api/upload-profilesGET, POSTList profiles; create/import a profile.
/api/upload-profiles/{id}PUT, DELETEUpdate an owned profile using its revision or delete it.
/api/upload-profiles/{id}/exportGETExport a portable profile recipe.
/api/upload-profiles/defaultPUTSelect or clear the account's default profile.
/api/customizationGETRead published appearance; administrators also receive draft/history state.
/api/customization/preferencesGET, PATCHRead/save personal appearance preference.
/api/profile/avatarPOSTUpload an account avatar.
/api/profile/sharexGETDownload a ShareX uploader configuration.
/api/profile/itakeGETDownload an iTake uploader configuration.
/api/profile/bashGETDownload the Bash uploader script.
/api/profile/flameshotPOSTGenerate a Flameshot script from submitted tool options.
/api/profile/spectaclePOSTGenerate a Spectacle script from submitted tool options.
/api/profile/export/progressGETStream account-export progress using server-sent events.
/api/files/{id}PATCH, DELETEChange an owned file's visibility/password or delete it.

Profile and appearance mutations have explicit origin/content-type guards. Integration commands likewise enforce same-origin JSON and a bounded body size. Generated uploader configurations contain a credential and should be treated as private downloads.

Email account flows ​

Email enrollment and change operations use an account session that remains available for verification/recovery flows. They deliberately do not use upload bearer credentials.

PathMethodsAuthentication and purpose
/api/auth/email/statusGETSession; current verification, enrollment, change, and recovery eligibility.
/api/auth/email/enrollPOSTSession and recent identity/password requirements; begin local verification enrollment.
/api/auth/email/changePOSTSession and identity/policy checks; request an address change.
/api/auth/email/resendPOSTSession; resend an eligible pending verification.
/api/auth/email/cancel-changePOSTSession; cancel the pending address change.
/api/auth/email/request-resetPOSTPublic recovery request, rate-limited with a generic eligibility response.
/api/auth/email/resetPOSTA valid one-time reset token and new password; not an API bearer token.
/api/auth/email/verifyPOSTA valid one-time email action token.
/api/auth/email/capabilitiesGETPublic view of enabled email capabilities.

Email session mutations validate the request origin when provided. Password/identity confirmation, feature enablement, verified-address policy, and cooldowns are additional checks beyond the authentication column.

Dashboard routes using the shared account helper ​

These routes use requireAuth, whose compatibility path accepts a browser session or the legacy account upload token. They are absent from the named-token allowlist, so an flr_… token cannot authorize them. This is why the legacy token should not be described as a narrowly scoped credential.

PathMethodsPurpose
/api/profilePUT, DELETEUpdate the account or delete it, subject to route-specific safeguards.
/api/profile/upload-tokenGET, POSTRead or regenerate the legacy account upload credential.
/api/profile/exportGETExport account data/files.
/api/files/{id}/expiryGET, POST, DELETEInspect, schedule, or cancel expiration for an owned file.
/api/foldersGET, POSTList or create folders.
/api/folders/{id}PATCH, DELETERename/move or delete an owned folder.
/api/files/foldersPOSTMove owned files into a folder or make them unfiled.
/api/tagsGET, POSTList or create tags and their rules.
/api/tags/{id}PATCH, DELETEEdit or delete an owned tag.
/api/tags/{id}/applyPOSTApply a tag's rule to existing files.
/api/files/tagsPATCHChange tag associations for selected owned files.

Folder/tag mutations also require their origin and content-type guards. This table describes actual authentication code, not a recommendation to use the legacy token to automate account changes. New integrations should use the documented named-token API, and people should use the dashboard for these operations.

Administrator session routes ​

These operations require a signed-in administrator. Named tokens do not inherit an administrator's authority.

PathMethodsPurpose
/api/usersGET, POST, PUTList, create, or edit users.
/api/users/{id}DELETEDelete a user.
/api/users/{id}/avatarDELETERemove a user's avatar.
/api/users/{id}/sessionsDELETEInvalidate a user's sessions.
/api/users/{id}/emailGET, POSTView email-policy state and perform permitted administrator email actions.
/api/users/{id}/filesGETInspect a user's file list.
/api/users/{id}/files/{fileId}PATCH, DELETEChange file access settings or remove a user's file.
/api/users/{id}/urlsGETInspect a user's short links.
/api/users/{id}/loginPOSTFetch target-user information used by the administrator's account-switching flow; this endpoint alone does not issue a login session.
/api/settingsPATCH, POSTUpdate a settings section or legacy whole-settings payload. Email/customization use their dedicated routes.
/api/settings/faviconPOSTUpload a legacy instance favicon.
/api/settings/emailGET, PUTRead/save email configuration and diagnostics.
/api/settings/email/impactGET, POSTPreview the affected users for saved or proposed email policy.
/api/settings/email/testPOSTTest SMTP connection or send a test message.
/api/settings/email/retryPOSTRetry an eligible mail-outbox entry.
/api/customizationPOSTSave/import/publish/restore appearance using action commands.
/api/customization/assetsPOSTUpload a validated appearance asset.
/api/updates/checkGETCheck for a newer Flare release.

Email administration validates origins for mutations; appearance administration uses explicit same-origin/content-type guards. Role checks are independent of these request guards.

Public and bootstrap routes ​

PathMethodsAuthentication and purpose
/api/healthGETPublic process liveness: { "success": true, "data": { "status": "ok" } }. Does not probe PostgreSQL or storage.
/api/storage/typeGETPublic storage kind (local or s3); falls back to local on an initialization error. Not a storage health check.
/api/setup/checkGETPublic setup-completion state.
/api/setupPOSTFirst-run bootstrap only while no users exist; creates the initial administrator/settings atomically and rate-limits attempts.
/api/auth/registration-statusGETPublic registration availability and message.
/api/auth/registerPOSTPublic account creation, subject to registration settings, validation, email policy, and rate limits.
/api/auth/{nextauth}GET, POSTNextAuth session, sign-in/out, provider, CSRF, and callback flows; protocol-specific protections apply.
/api/settingsGETReturns public settings anonymously or to non-admins; an authenticated administrator through the shared helper receives the fuller settings view. Named tokens receive only the public fallback.
/api/faviconGETServe the configured favicon/fallback.
/api/avatars/{filename}GETServe an avatar image.

Public does not mean unrestricted mutation: registration can be closed and bootstrap stops once a user exists. Email one-time-token routes are listed separately because possession of the relevant action token is their authorization.

Maintaining an integration ​

Build new automation against the named-token routes and their OpenAPI schemas. For dashboard behavior, treat route bodies and session flows as application internals that can evolve with Flare. There is currently no named-token administrator API, no general token-authorized file deletion/download API, and no chunk-cancel endpoint.

The route inventory is checked against the source tree when the documentation is validated, so a newly added route prompts a documentation update instead of silently expanding a token's authority.