# API Reference This reference covers v1.18.0; consult the [changelog](../CHANGELOG.md) for release changes. Unversioned `/api/*` routes have been removed; use `/api/v1/*`. All endpoints require either a `digarr_session` cookie or an `Authorization: Bearer ` header unless marked as public. Bearer sessions remain the compatibility path for non-browser API clients. Only `/api/v1/pipeline/events` and `/api/v1/preview/audio` also accept `?token=` for SSE and `