Control endpoints
The control API uses JSON for its structured responses. It runs on the configured control.bind_address and a port two above the proxy listener. A token file, when configured and nonempty, makes every route require X-404-Control-Token. Never bind an unauthenticated control listener to a public interface.
Lifecycle and certificates
| Request | Current response or effect |
|---|---|
GET /status | { "mode": "proxy", "ready": true } when the proxy is ready; mode can also be control. |
POST /stop | { "stopping": true }; requests process shutdown. |
GET /ca/status | Certificate path, existence flag, and public cert_pem (empty if no file yet). |
POST /ca/init | Initializes CA material if needed and returns path, existence, and public PEM. |
The CA private key is not returned from these endpoints. Trust installation belongs to the host or operator. See TLS and certificates.
Profiles and telemetry
| Request | Current response or effect |
|---|---|
GET /profiles/catalog | active_profile and profiles array; entries include key, display name, family, variant, and platform. |
GET /profiles/active | Current active_profile or null. |
POST /profiles/select | Accepts { "profile": "chrome-windows" }; returns the selected active_profile, or 400 if unknown. |
POST /profiles/validate | Accepts { "profile": { … } }; returns { "warnings": [ … ] } for coherence issues. |
GET /telemetry/snapshot | { "events": [ … ] } from the bounded in-process buffer. |
Profile selection affects new Flows and triggers an attempted Linux packet map sync. Validation returns warnings; it does not install the submitted profile. Telemetry snapshots are process-local, not durable. Inspect control.rs for the exact current schema and Profile anatomy for the profile data model.