Udon is under active development. Documentation not final.
udonudon

API reference

How to authenticate against Udon's HTTP API, the roles it checks, and its main HTTP and WebSocket endpoints.

The daemon udond serves a JSON HTTP API on the same HTTPS port as the web UI (4443 by default). The web UI is built on this API, and it is stable enough to script against. The tables below cover the main endpoints; the pages under this section document every one, with its request and response.

Authentication

Auth is a session cookie named udon_session. It is HttpOnly, SameSite=Strict, and marked Secure over TLS. Sign in with POST /api/auth/login; the response sets the cookie. Send the cookie on every later request. WebSocket upgrades use the same cookie.

Every endpoint also accepts Authorization: Bearer <token>. Send an X-Udon-Client header with the login request to get a token in the response body instead of the cookie.

Roles, from least to most access:

  • viewer: read most data.
  • operator: viewer, plus run and manage containers, images, and files.
  • admin: operator, plus user management, system and network settings, privileged actions.

An endpoint's required role is listed below. A higher role always satisfies a lower requirement.

Errors come back as JSON with a human-readable message and an HTTP status (400 invalid input, 401 not signed in, 402 license locked, 403 wrong role, 404 missing, 409 conflict, 423 Admin Privileges or Full Disk Access missing, 503 engine or helper unavailable, or an update still finishing).

Health and setup

MethodPathRolePurpose
GET/healthnoneDaemon liveness and version.
GET/api/setupnoneWhether the first account still needs creating.
POST/api/setupnoneCreate the first admin (only before any user exists).

Auth

MethodPathRolePurpose
POST/api/auth/loginnoneSign in with username and password.
POST/api/auth/logoutviewerEnd the session.
GET/api/auth/meviewerThe signed-in user.

Users

MethodPathRolePurpose
GET/api/usersadminList users.
POST/api/usersadminCreate a user (username, password, role).
POST/api/users/:id/roleadminChange a user's role.
POST/api/users/:id/disabledadminEnable or disable a user.
POST/api/users/:id/passwordadminReset a user's password.
POST/api/users/:id/removeadminDelete a user.
POST/api/me/passwordviewerChange your own password.

Containers and images

MethodPathRolePurpose
GET/api/system/engineviewerContainer engine status.
GET/api/containersviewerList containers.
GET/api/containers/:idviewerInspect a container (raw engine JSON).
GET/api/containers/:id/statsviewerResource stats.
GET/api/containers/:id/logsviewerRecent logs as text.
POST/api/containersoperatorRun a container from a RunSpec.
POST/api/containers/:id/startoperatorStart.
POST/api/containers/:id/stopoperatorStop.
POST/api/containers/:id/restartoperatorRestart.
POST/api/containers/:id/killoperatorKill.
POST/api/containers/:id/removeoperatorRemove (force optional).
GET/api/imagesviewerList images.
POST/api/images/pulloperatorPull an image by reference.
POST/api/images/deleteoperatorDelete an image by reference.
GET/api/networksviewerList container networks.
POST/api/networksoperatorCreate a network.
POST/api/networks/:name/deleteoperatorDelete a network.

A RunSpec carries image plus optional name, command, ports, env, volumes, cpus, memory, workdir, network, and a set of advanced fields (entrypoint, user, capabilities, DNS, mounts, tmpfs, devices, extra flags).

System

MethodPathRolePurpose
GET/api/versionviewerDaemon version and commit.
GET/api/system/infoviewerHardware and OS facts.
GET/api/system/networkviewerNetwork interface summary.
GET/api/system/settingsviewerRead-only host settings snapshot.
GET/api/auditadminActivity log. Query range (24h/7d/30d/all), limit, offset.
GET/api/system/desktopadminScreen Sharing status and connect URL.
POST/api/system/power/sleepadminSleep the Mac.
POST/api/system/power/display-sleepadminSleep the display.
POST/api/system/power/restartadminRestart the Mac.
POST/api/system/power/shutdownadminShut down the Mac.
GET/api/updatesviewerThe last update check's result.
POST/api/updates/installadminInstall the update and restart.

Network configuration

Admin, and requires Admin Privileges. Every value is validated by the root helper and run as argv.

MethodPathPurpose
GET/api/system/network/servicesList configurable network services.
POST/api/system/network/services/:service/dnsSet DNS servers.
POST/api/system/network/services/:service/ipv4Switch to DHCP or set a manual IPv4.
POST/api/system/network/services/:service/enabledEnable or disable the service.

Admin Privileges

MethodPathRolePurpose
GET/api/system/privilegedviewerHelper status and the list of privileged actions.
POST/api/system/privileged/:keyadminApply one allowlisted action (choice on/off/set, optional value).

Storage and files

MethodPathRolePurpose
GET/api/storageviewerDisks, volumes, container volumes, roots, and mounted shares.
GET/api/storage/smart/:idoperatorSMART report for a disk.
POST/api/storage/ejectadminEject a removable disk.
POST/api/storage/mountadminMount a network share.
POST/api/storage/unmountadminUnmount a network share.
GET/api/storage/exportsviewerFolders shared over SMB.
POST/api/storage/exportsadminShare a folder over SMB (path, name, readOnly, guestAccess).
POST/api/storage/exports/removeadminStop sharing a folder.
GET/api/storage/fs/listoperatorList a directory (root, path).
GET/api/storage/fs/readoperatorRead a text file (preview, capped).
GET/api/storage/fs/downloadoperatorDownload a file (supports range requests).
POST/api/storage/fs/uploadadminUpload a file (root, path, name, raw body).

App catalog

MethodPathRolePurpose
GET/api/catalogviewerInstallable apps from the catalog.

Dashboard, branding, icons, extensions

MethodPathRolePurpose
GET/api/bento/widgetsviewerDashboard widgets with cached output (script hidden for non-admins).
POST/api/bento/widgetsadminCreate a widget.
POST/api/bento/widgets/:id/updateadminEdit a widget.
POST/api/bento/widgets/:id/deleteadminDelete a widget.
POST/api/bento/widgets/:id/runoperatorRun a widget now.
GET/api/brandingnoneSign-in page branding: server name, headline, description and background.
PUT/api/brandingadminSet the server name.
GET/api/icons/container/:nameviewerCustom container icon.
PUT/api/icons/container/:nameoperatorUpload a container icon.
DELETE/api/icons/container/:nameoperatorClear a container icon.
GET/api/extensionsviewerInstalled shell extensions.

Tailscale

MethodPathRolePurpose
GET/api/tailscaleviewerStatus, peers, and remote-access state.
POST/api/tailscale/settingsadminApply preferences (accept routes/DNS, SSH, shields, exit node, hostname).
POST/api/tailscale/loginadminStart the login flow, returns an auth URL.
POST/api/tailscale/logoutadminDisconnect from the tailnet.
POST/api/tailscale/connectadminBring the tailnet up or down.
MethodPathRolePurpose
GET/api/brewviewerInstalled Homebrew packages.
GET/api/brew/searchviewerSearch Homebrew (q).
GET/api/dockerhub/searchviewerSearch Docker Hub (q).

Metrics

MethodPathRolePurpose
GET/api/metricsviewerOne host metrics snapshot.
GET/api/metrics/streamviewerServer-sent events, a sample every two seconds.

WebSocket endpoints

These upgrade over the session cookie or a bearer token, and a browser must open them from the dashboard's own address.

PathRolePurpose
/api/containers/installoperatorLive install output; first message is a RunSpec.
/api/containers/updateoperatorLive output of a batch container update.
/api/containers/logs?id=&tail=viewerA container's log, followed live.
/api/terminaladminInteractive shell on the host.
/api/desktopadminVNC bridge to the Mac's Screen Sharing.
/api/brew/execadminLive output of a Homebrew install, upgrade, or uninstall.

The terminal socket carries binary frames both ways, and accepts a text frame {"type":"resize","cols":N,"rows":N} to resize the pseudo-terminal.

Ask AI

Answers from Udon's documentation.

Ask how to install Udon, run containers, or share folders.