API Reference v1
Complete reference for the Aaxion REST API.
Base URL
http://localhost:8080/api/v1Auth Header
Bearer <token>Authentication
/api/v1/auth/registerPUBLICRegister the initial admin user. Fails if a user already exists.
curl -X POST \
-d '{"username":"admin","password":"mypassword"}' \
http://localhost:8080/api/v1/auth/register/api/v1/auth/loginAuthenticate and receive a session token and device info.
curl -X POST \
-d '{"username":"admin","password":"mypassword"}' \
http://localhost:8080/api/v1/auth/login/api/v1/auth/logoutInvalidate the current session token.
curl -X POST \
-H "Authorization: Bearer $TOKEN" \
http://localhost:8080/api/v1/auth/logout/api/v1/auth/token/generateGenerate a new short-lived access token (5 hours). Requires session token, not access token.
curl -X POST \
-H "Authorization: Bearer $SESSION_TOKEN" \
http://localhost:8080/api/v1/auth/token/generate/api/v1/auth/token/removeRemove all access tokens for a given token.
curl -X POST \
-H "Authorization: Bearer $TOKEN" \
-d '{"token":"token_to_clean"}' \
http://localhost:8080/api/v1/auth/token/removeFiles & Directories
/api/v1/files/view?dir={path}List contents of a directory. Returns files and folders as JSON.
curl -H "Authorization: Bearer $TOKEN" \
"http://localhost:8080/api/v1/files/view?dir=/home/user"/api/v1/files/directory/create?path={path}Create a new directory at the specified path.
curl -X POST \
-H "Authorization: Bearer $TOKEN" \
"http://localhost:8080/api/v1/files/directory/create?path=/home/user/new_folder"/api/v1/files/unzipExtract a ZIP archive. If dest_dir is omitted, it extracts to the zip's folder.
curl -X POST \
-H "Authorization: Bearer $TOKEN" \
-d '{"zip_path":"/home/user/archive.zip","dest_dir":"/home/user/output"}' \
http://localhost:8080/api/v1/files/unzipUpload & Download
/api/v1/files/upload?dir={path}Upload a single file via multipart/form-data. Field name: file.
curl -F "file=@/path/to/file.txt" \
-H "Authorization: Bearer $TOKEN" \
"http://localhost:8080/api/v1/files/upload?dir=/home/user"/api/v1/files/download?path={file}Download a file. Supports token via ?tkn= query param.
curl -O \
-H "Authorization: Bearer $TOKEN" \
"http://localhost:8080/api/v1/files/download?path=/home/user/file.txt"Chunked Uploads
Three-step flow for multi-GB files: initialize, stream parts, then merge.
/api/v1/files/upload/chunk/start?filename={name}Step 1 — Initialize a chunked upload session.
curl -X POST \
-H "Authorization: Bearer $TOKEN" \
"http://localhost:8080/api/v1/files/upload/chunk/start?filename=big.zip"/api/v1/files/upload/chunk?filename={name}&chunk_index={idx}Step 2 — Upload a single binary chunk (raw body, NOT multipart). Keep under 90MB.
curl --data-binary @part0.bin \
-H "Authorization: Bearer $TOKEN" \
"http://localhost:8080/api/v1/files/upload/chunk?filename=big.zip&chunk_index=0"/api/v1/files/upload/chunk/complete?filename={name}&dir={path}Step 3 — Merge all chunks into the final file.
curl -X POST \
-H "Authorization: Bearer $TOKEN" \
"http://localhost:8080/api/v1/files/upload/chunk/complete?filename=big.zip&dir=/home/user"Media & Images
/api/v1/images/thumbnail?path={file}Get a resized 200px JPEG thumbnail. Supports ?tkn=<token> for img tags.
curl -H "Authorization: Bearer $TOKEN" \
"http://localhost:8080/api/v1/images/thumbnail?path=/home/user/photo.jpg"/api/v1/images/view?path={file}Full-resolution image with 7-day client-side cache. Supports ?tkn= query param.
curl -H "Authorization: Bearer $TOKEN" \
"http://localhost:8080/api/v1/images/view?path=/home/user/photo.jpg"/api/v1/files/stream?path={file}Zero-buffer stream a video or audio file. Supports HTTP Range for seeking and ?tkn= query param.
curl -H "Authorization: Bearer $TOKEN" \
"http://localhost:8080/api/v1/files/stream?path=/home/user/video.mp4"Anonymous Uploads
Token-based uploads for external users. Admin generates tokens, guests upload with them.
/api/v1/anonymous/token/generateAdmin: Create a new upload token. Configure via query params.
curl -X POST \
-H "Authorization: Bearer $TOKEN" \
"http://localhost:8080/api/v1/anonymous/token/generate?target_dir=/uploads&max_uploads=5&expiry_hours=48&max_file_size=1073741824"/api/v1/anonymous/token/revoke?token={token}Admin: Revoke an existing upload token.
curl -X POST \
-H "Authorization: Bearer $TOKEN" \
"http://localhost:8080/api/v1/anonymous/token/revoke?token=abc123"/api/v1/anonymous/tokensAdmin: List all active upload tokens.
curl -H "Authorization: Bearer $TOKEN" \
http://localhost:8080/api/v1/anonymous/tokens/api/v1/anonymous/token/info?token={token}Admin: Get details about a specific upload token.
curl -H "Authorization: Bearer $TOKEN" \
"http://localhost:8080/api/v1/anonymous/token/info?token=abc123"/api/v1/anonymous/token/validate?token={token}PUBLICGuest: Check if a token is valid before uploading.
curl -X POST "http://localhost:8080/api/v1/anonymous/token/validate?token=abc123"/api/v1/anonymous/upload?token={token}PUBLICGuest: Upload a file using a valid upload token.
curl -F "file=@/path/to/file.txt" \
"http://localhost:8080/api/v1/anonymous/upload?token=abc123"/api/v1/anonymous/upload/chunk/start?token={token}&filename={name}PUBLICGuest: Start chunked upload with token.
curl -X POST \
"http://localhost:8080/api/v1/anonymous/upload/chunk/start?token=abc123&filename=big.zip"/api/v1/anonymous/upload/chunk?token={token}&filename={name}&chunk_index={idx}PUBLICGuest: Upload a binary chunk.
curl --data-binary @part0.bin \
"http://localhost:8080/api/v1/anonymous/upload/chunk?token=abc123&filename=big.zip&chunk_index=0"/api/v1/anonymous/upload/chunk/complete?token={token}&filename={name}PUBLICGuest: Complete chunked upload.
curl -X POST \
"http://localhost:8080/api/v1/anonymous/upload/chunk/complete?token=abc123&filename=big.zip"System
/api/v1/system/infoPUBLICServer version, codename, OS, architecture. No auth required.
curl http://localhost:8080/api/v1/system/info/api/v1/system/root-pathGet the monitored root directory.
curl -H "Authorization: Bearer $TOKEN" \
http://localhost:8080/api/v1/system/root-path/api/v1/system/storageDisk usage statistics including external devices.
curl -H "Authorization: Bearer $TOKEN" \
http://localhost:8080/api/v1/system/storageMovies
Legacy endpoints. Not actively developed.
/api/v1/moviesList all movies.
curl -H "Authorization: Bearer $TOKEN" \
http://localhost:8080/api/v1/movies/api/v1/movies/search?q={query}Search movies by title or description.
curl -H "Authorization: Bearer $TOKEN" \
"http://localhost:8080/api/v1/movies/search?q=inter"/api/v1/movies/addAdd a new movie entry.
curl -X POST \
-H "Authorization: Bearer $TOKEN" \
-d '{"title":"Interstellar","file_path":"/media/movies/interstellar.mp4","file_id":10,"description":"A great movie","poster_path":"/media/posters/interstellar.jpg"}' \
http://localhost:8080/api/v1/movies/add/api/v1/movies/editEdit an existing movie.
curl -X PUT \
-H "Authorization: Bearer $TOKEN" \
-d '{"id":1,"title":"Updated Title","description":"Updated description","poster_path":"/media/posters/updated.jpg"}' \
http://localhost:8080/api/v1/movies/edit/api/v1/movies/stream?id={id}Stream a movie. Supports HTTP Range and ?tkn= query param.
curl -H "Authorization: Bearer $TOKEN" \
"http://localhost:8080/api/v1/movies/stream?id=1"Series & Episodes
Legacy endpoints. Not actively developed.
/api/v1/seriesList all series.
curl -H "Authorization: Bearer $TOKEN" \
http://localhost:8080/api/v1/series/api/v1/series/search?q={query}Search series by title.
curl -H "Authorization: Bearer $TOKEN" \
"http://localhost:8080/api/v1/series/search?q=breaking"/api/v1/series/addCreate a new series.
curl -X POST \
-H "Authorization: Bearer $TOKEN" \
-d '{"title":"Stranger Things","description":"Sci-fi horror drama."}' \
http://localhost:8080/api/v1/series/add/api/v1/series/editEdit an existing series.
curl -X PUT \
-H "Authorization: Bearer $TOKEN" \
-d '{"id":1,"title":"Updated Title","description":"Updated description"}' \
http://localhost:8080/api/v1/series/edit/api/v1/series/episodes?series_id={id}List episodes for a series.
curl -H "Authorization: Bearer $TOKEN" \
"http://localhost:8080/api/v1/series/episodes?series_id=1"/api/v1/series/episodes/addAdd an episode to a series.
curl -X POST \
-H "Authorization: Bearer $TOKEN" \
-d '{"series_id":1,"file_id":10,"file_path":"/media/series/s01e01.mp4","season_number":1,"episode_number":1,"title":"Chapter One","description":"The first chapter"}' \
http://localhost:8080/api/v1/series/episodes/add/api/v1/series/episodes/stream?id={id}Stream an episode. Supports HTTP Range and ?tkn= query param.
curl -H "Authorization: Bearer $TOKEN" \
"http://localhost:8080/api/v1/series/episodes/stream?id=101"Music
Music tracks, streaming, and play statistics. No auth middleware on these routes.
/api/v1/musicPUBLICGet all music tracks.
curl http://localhost:8080/api/v1/music/api/v1/music/get?id={id}PUBLICGet a single track by ID.
curl "http://localhost:8080/api/v1/music/get?id=1"/api/v1/music/search?title={query}PUBLICSearch tracks by title. Note: query param is 'title', not 'q'.
curl "http://localhost:8080/api/v1/music/search?title=bohemian"/api/v1/music/add?uri={youtube_url}PUBLICAdd a track by URI (downloads via yt-dlp). Uses form value, not JSON.
curl -X POST \
"http://localhost:8080/api/v1/music/add?uri=https://youtube.com/watch?v=..."/api/v1/music/updatePUBLICUpdate an existing track's metadata via JSON body.
curl -X PUT \
-d '{"id":1,"title":"Updated Title","artist":"Updated Artist","album":"Updated Album","duration":210.5,"releaseYear":2024,"filePath":"/path/to/song.mp3","ytUri":"https://youtube.com/watch?v=...","imagePath":"/path/to/cover.jpg","size":5000000,"createdAt":"2026-09-15T..."}' \
http://localhost:8080/api/v1/music/update/api/v1/music/stream?id={id}PUBLICStream an audio track via http.ServeFile.
curl "http://localhost:8080/api/v1/music/stream?id=1"/api/v1/music/stats/play?track_id={id}PUBLICRecord a play event. Params via query or form values.
curl -X POST \
"http://localhost:8080/api/v1/music/stats/play?track_id=1"/api/v1/music/stats/favorite?track_id={id}&is_favorite={bool}PUBLICToggle favorite status. Params via query or form values.
curl -X POST \
"http://localhost:8080/api/v1/music/stats/favorite?track_id=1&is_favorite=true"/api/v1/music/stats/play-state?track_id={id}PUBLICGet play state for a track.
curl "http://localhost:8080/api/v1/music/stats/play-state?track_id=1"/api/v1/music/stats/play-statesPUBLICGet play states for all tracks.
curl http://localhost:8080/api/v1/music/stats/play-states/api/v1/music/stats/is-favorite?track_id={id}PUBLICCheck if a track is favorited.
curl "http://localhost:8080/api/v1/music/stats/is-favorite?track_id=1"/api/v1/music/stats/last-playedPUBLICGet the last played track.
curl http://localhost:8080/api/v1/music/stats/last-playedWebSockets & Devices
/api/v1/devicesPUBLICList all currently connected WebSocket devices.
curl http://localhost:8080/api/v1/devices/api/v1/ws?deviceId={id}&deviceName={name}PUBLICWebSocket endpoint. Connect with optional deviceId and deviceName query params.
wscat -c "ws://localhost:8080/api/v1/ws?deviceId=phone-1&deviceName=MyPhone"