API Playground

What the playground restricts, and why

The console talks to a real node — possibly a production one, like k16. The rule that decides what runs live is simple: a route executes in the browser only if failing to notice a mistake there costs nothing. Everything else renders a curl command instead, so you read it before it runs anywhere.

The rule

✅
Executes live

Every GET — nothing a GET does is supposed to change state — plus the two POST routes whose worst case is cheap and reversible: creating a chat completion, and creating a new API key.

🔒
curl only

Anything that revokes access, moves funds, changes what network or model the node is on, writes a file to disk, or turns on sending prompts to a third-party API. The console builds the exact command and you run it in your own terminal.

Every route, by policy

RoutePolicyReason
GET /v1/modelsLiveRead-only, no key needed
POST /v1/chat/completionsLiveWorst case: one paid or free completion, same as using the chat panel
GET /v1/nodesLiveRead-only
GET /v1/agentLiveRead-only, no key needed
POST /v1/agent/launchcurl onlyChanges whether this machine is on the P2P network
GET /v1/swarm/manifestLiveRead-only
POST /v1/swarm/manifestcurl onlyRe-signs the manifest and can trigger a real model load
GET /v1/routing-logLiveRead-only
GET /v1/keysLiveRead-only (already needs a key to call)
POST /v1/keysLiveAdditive and reversible — a new key can be revoked
DELETE /v1/keys/:idcurl onlyRevokes access; could be the key the console itself is using
POST /v1/keys/revoke-allcurl onlyRevokes every key, including the panel's own
GET /v1/quota, /v1/budget, /v1/budget/reportLiveRead-only
GET /v1/receipts/:idLiveRead-only, no key needed
GET /v1/wallet, /v1/wallet/balances, /v1/wallet/historyLiveRead-only
POST /v1/wallet/send/quote, /v1/wallet/sendcurl onlyMoves real funds; send needs confirmar: "MAINNET" on mainnet
POST /v1/wallet/createcurl onlyGenerates key material; the 24-word phrase is shown once
POST /v1/wallet/networkcurl onlyChanges which chain the node talks to; requires a restart
POST / DELETE /v1/wallet/tokenscurl onlyEdits what the wallet watches
GET /v1/filesLiveRead-only
POST /v1/files/upload, /v1/files/fetchcurl onlyWrites bytes to this node's disk and Hyperdrive
GET /v1/upstreamLiveRead-only
POST /v1/upstream/opt-incurl onlyThe one switch that can send a prompt to a third-party API

CORS: why a live request might fail anyway

The console runs as a page on this origin and calls the Base URL you give it — typically your node on the LAN, such as k16. That is a cross-origin request by definition, and the browser will only let the response through if the node's gateway sends back an Access-Control-Allow-Origin header that permits it.

If the console reports a network error rather than a status code, this is almost always why. Two ways to fix it:

Testing against k16

Set Base URL to wherever k16's gateway listens — its LAN address and port, e.g. http://k16.local:8787 or an IP:port — and paste in a key created from that node's My Node panel or via POST /v1/keys run directly against it. The connection fields are saved only in this browser's localStorage, so the key never leaves your machine except in the request itself.