API overview
STATIC exposes a local control API on a separate listener from browsing traffic. The desktop application and operators use it to inspect readiness, retrieve the public CA certificate, read and select profiles, view a recent telemetry snapshot, and request shutdown. The API does not proxy browsing requests.
Endpoint groups
| Group | Routes |
|---|---|
| Lifecycle | GET /status, POST /stop |
| Certificates | GET /ca/status, POST /ca/init |
| Profiles | GET /profiles/catalog, GET /profiles/active, POST /profiles/select, POST /profiles/validate |
| Observability | GET /telemetry/snapshot |
The port is the configured proxy listener port plus two. If a nonempty control.token_path is configured, send X-404-Control-Token on every request. Keep this listener on loopback; without a configured token the implementation performs no token check. See Control plane and CA for the current behavior and control.rs for route definitions.
Next in this section
Continue to Control endpoints for request and response shapes. Further API reference pages can be added to this section as the migration proceeds.