swagger: '2.0' info: contact: email: info@portainer.io description: 'Portainer API is an HTTP API served by Portainer. It is used by the Portainer UI and everything you can do with the UI can be done using the HTTP API. Examples are available at https://documentation.portainer.io/api/api-examples/ You can find out more about Portainer at [http://portainer.io](http://portainer.io) and get some support on [Slack](http://portainer.io/slack/). # Authentication Most of the API environments(endpoints) require to be authenticated as well as some level of authorization to be used. Portainer API uses JSON Web Token to manage authentication and thus requires you to provide a token in the **Authorization** header of each request with the **Bearer** authentication mechanism. Example: ``` Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6MSwidXNlcm5hbWUiOiJhZG1pbiIsInJvbGUiOjEsImV4cCI6MTQ5OTM3NjE1NH0.NJ6vE8FY1WG6jsRQzfMqeatJ4vh2TWAeeYfDhP71YEE ``` # Security Each API environment(endpoint) has an associated access policy, it is documented in the description of each environment(endpoint). Different access policies are available: - Public access - Authenticated access - Restricted access - Administrator access ### Public access No authentication is required to access the environments(endpoints) with this access policy. ### Authenticated access Authentication is required to access the environments(endpoints) with this access policy. ### Restricted access Authentication is required to access the environments(endpoints) with this access policy. Extra-checks might be added to ensure access to the resource is granted. Returned data might also be filtered. ### Administrator access Authentication as well as an administrator role are required to access the environments(endpoints) with this access policy. # Execute Docker requests Portainer **DO NOT** expose specific environments(endpoints) to manage your Docker resources (create a container, remove a volume, etc...). Instead, it acts as a reverse-proxy to the Docker HTTP API. This means that you can execute Docker requests **via** the Portainer HTTP API. To do so, you can use the `/endpoints/{id}/docker` Portainer API environment(endpoint) (which is not documented below due to Swagger limitations). This environment(endpoint) has a restricted access policy so you still need to be authenticated to be able to query this environment(endpoint). Any query on this environment(endpoint) will be proxied to the Docker API of the associated environment(endpoint) (requests and responses objects are the same as documented in the Docker API). # Private Registry Using private registry, you will need to pass a based64 encoded JSON string ‘{"registryId":\}’ inside the Request Header. The parameter name is "X-Registry-Auth". \ - The registry ID where the repository was created. Example: ``` eyJyZWdpc3RyeUlkIjoxfQ== ``` **NOTE**: You can find more information on how to query the Docker API in the [Docker official documentation](https://docs.docker.com/engine/api/v1.30/) as well as in [this Portainer example](https://documentation.portainer.io/api/api-examples/). ' license: name: zlib url: https://github.com/portainer/portainer/blob/develop/LICENSE title: PortainerCE auth websocket API version: 2.39.1 basePath: /api schemes: - http - https tags: - description: Create exec sessions using websockets name: websocket paths: /websocket/attach: get: consumes: - application/json description: 'If the nodeName query parameter is present, the request will be proxied to the underlying agent environment(endpoint). If the nodeName query parameter is not specified, the request will be upgraded to the websocket protocol and an AttachStart operation HTTP request will be created and hijacked. **Access policy**: authenticated' parameters: - description: environment(endpoint) ID of the environment(endpoint) where the resource is located in: query name: endpointId required: true type: integer - description: node name in: query name: nodeName type: string - description: JWT token used for authentication against this environment(endpoint) in: query name: token required: true type: string produces: - application/json responses: '200': description: OK '400': description: Bad Request '403': description: Forbidden '404': description: Not Found '500': description: Internal Server Error security: - ApiKeyAuth: [] - jwt: [] summary: Attach a websocket tags: - websocket /websocket/exec: get: consumes: - application/json description: 'If the nodeName query parameter is present, the request will be proxied to the underlying agent environment(endpoint). If the nodeName query parameter is not specified, the request will be upgraded to the websocket protocol and an ExecStart operation HTTP request will be created and hijacked.' parameters: - description: environment(endpoint) ID of the environment(endpoint) where the resource is located in: query name: endpointId required: true type: integer - description: node name in: query name: nodeName type: string - description: JWT token used for authentication against this environment(endpoint) in: query name: token required: true type: string produces: - application/json responses: '200': description: OK '400': description: Bad Request '409': description: Conflict '500': description: Internal Server Error security: - ApiKeyAuth: [] - jwt: [] summary: Execute a websocket tags: - websocket /websocket/kubernetes-shell: get: consumes: - application/json description: 'The request will be upgraded to the websocket protocol. The request will proxy input from the client to the pod via long-lived websocket connection. **Access policy**: authenticated' parameters: - description: environment(endpoint) ID of the environment(endpoint) where the resource is located in: query name: endpointId required: true type: integer - description: JWT token used for authentication against this environment(endpoint) in: query name: token required: true type: string produces: - application/json responses: '200': description: Success '400': description: Invalid request '403': description: Permission denied '500': description: Server error security: - ApiKeyAuth: [] - jwt: [] summary: Execute a websocket on kubectl shell pod tags: - websocket /websocket/pod: get: consumes: - application/json description: 'The request will be upgraded to the websocket protocol. **Access policy**: authenticated' parameters: - description: environment(endpoint) ID of the environment(endpoint) where the resource is located in: query name: endpointId required: true type: integer - description: namespace where the container is located in: query name: namespace required: true type: string - description: name of the pod containing the container in: query name: podName required: true type: string - description: name of the container in: query name: containerName required: true type: string - description: command to execute in the container in: query name: command required: true type: string - description: JWT token used for authentication against this environment(endpoint) in: query name: token required: true type: string produces: - application/json responses: '200': description: OK '400': description: Bad Request '403': description: Forbidden '404': description: Not Found '500': description: Internal Server Error security: - ApiKeyAuth: [] - jwt: [] summary: Execute a websocket on pod tags: - websocket securityDefinitions: ApiKeyAuth: in: header name: X-API-KEY type: apiKey jwt: in: header name: Authorization type: apiKey