tnl.dev :: docs

api contracts.

Browse tnl's OpenAPI contracts and find the project config schema.

public control and authority apis

The five HTTP API contracts are published as OpenAPI 3.1 files. Use the interactive API reference below to browse operations and schemas, or download a spec for code generation. The spec's servers entry is illustrative; replace it with your control URL or the appropriate private endpoint.

  • Control API spec (source): discovery, health and readiness, public URLs, publish runs, certificates, and administrator controls. GET /v1/health and GET /v1/ready are unauthenticated; mutating public URL and administrator operations require the appropriate bearer session or publish run credential.
  • Authority API spec (source): login and refresh, identities, teams, memberships, invitations, domains, and authorization. Control or standalone serves the built-in authority; an external authority can be deployed separately.

private and receiver apis

  • Ingress API spec (source): process registration and lease renewal, routing-table updates, and usage reporting to control.
  • Relay API spec (source): process leases, connection claims, and relay transport certificates. Ingress and relay APIs use cluster authentication on the private control endpoint; they are not public visitor endpoints.
  • Public URL usage API spec (source): optional authenticated bucket-report delivery from control to a configured external receiver. Configure TNLD_PUBLIC_URL_USAGE_URL and TNLD_PUBLIC_URL_USAGE_TOKEN together to enable it.

Visitor TLS and publisher connections use the separate tunnel protocol, not these HTTP OpenAPI schemas. For the server roles and network boundaries, see self-hosting.

interactive reference

Select one of the five specs in the reference's menu. The embedded viewer disables request submission; use an authenticated client or tnl to call your own server.