404PrivacyDocs

Control endpoints

The control API uses JSON for its structured responses. It runs on the configured control.bind_address and a port two above the proxy listener. A token file, when configured and nonempty, makes every route require X-404-Control-Token. Never bind an unauthenticated control listener to a public interface.

Lifecycle and certificates

RequestCurrent response or effect
GET /status{ "mode": "proxy", "ready": true } when the proxy is ready; mode can also be control.
POST /stop{ "stopping": true }; requests process shutdown.
GET /ca/statusCertificate path, existence flag, and public cert_pem (empty if no file yet).
POST /ca/initInitializes CA material if needed and returns path, existence, and public PEM.

The CA private key is not returned from these endpoints. Trust installation belongs to the host or operator. See TLS and certificates.

Profiles and telemetry

RequestCurrent response or effect
GET /profiles/catalogactive_profile and profiles array; entries include key, display name, family, variant, and platform.
GET /profiles/activeCurrent active_profile or null.
POST /profiles/selectAccepts { "profile": "chrome-windows" }; returns the selected active_profile, or 400 if unknown.
POST /profiles/validateAccepts { "profile": { … } }; returns { "warnings": [ … ] } for coherence issues.
GET /telemetry/snapshot{ "events": [ … ] } from the bounded in-process buffer.

Profile selection affects new Flows and triggers an attempted Linux packet map sync. Validation returns warnings; it does not install the submitted profile. Telemetry snapshots are process-local, not durable. Inspect control.rs for the exact current schema and Profile anatomy for the profile data model.