-
Notifications
You must be signed in to change notification settings - Fork 0
API and Configuration
Home · Previous: Replay and Idempotency · Next: Architecture and Security
Default base URL: http://127.0.0.1:8000. Interactive API documentation is available at /docs while the app is running.
All /api/* endpoints require Authorization: Bearer <admin token>. The inbox has its own private path token; do not confuse it with the administrator token.
| Method | Path | Authentication | Purpose |
|---|---|---|---|
| GET | /health |
None | Database connectivity and app version |
| POST | /in/{inbox_token} |
Inbox path token | Persist body and sanitized headers |
| GET | /api/config |
Admin bearer | Inbox path and named destinations |
| GET | /api/events?limit=20&offset=0 |
Admin bearer | Paginated events and aggregate counts |
| GET | /api/events/{id} |
Admin bearer | Body preview, exact base64 body and history |
| GET | /api/events/{id}/body |
Admin bearer | Download original body as attachment |
| POST | /api/events/{id}/replay |
Admin bearer | Record and perform one replay attempt |
POST /api/events/EVENT_ID/replay
Authorization: Bearer YOUR_ADMIN_TOKEN
Content-Type: application/json
{"target":"demo-success"}Replace the placeholders using your local configuration and a captured event ID. Choose a target returned by /api/config. A caller cannot submit an arbitrary destination URL.
A 200 from the replay API means the attempt was recorded. Inspect its status and status_code to determine delivery outcome. A destination's 2xx does not prove its business operation succeeded.
Set variables in the shell that launches the app; restart after changing configuration.
| Variable | Default | Meaning |
|---|---|---|
WLAB_HOST |
127.0.0.1 |
Bind address; keep local for this prototype |
WLAB_PORT |
8000 |
Listening port |
WLAB_DATA_DIR |
data |
SQLite and generated token directory, relative to current working directory |
WLAB_ADMIN_TOKEN |
Generated locally | Administrator token, minimum 24 characters; choose a random value |
WLAB_TARGETS |
{} |
JSON object mapping names to HTTP(S) URLs |
When no administrator token is supplied, the app creates or reuses data/admin.token. With a custom data directory, read the token there instead. Do not commit tokens or data files.
- Target names must be nonempty and cannot begin with
demo-. - URLs must use HTTP or HTTPS and include a hostname.
- URL credentials, query strings and fragments are rejected.
- Redirect following and environment proxy settings are disabled.
- Operator-controlled destinations are not a substitute for a hardened public egress gateway.
See Replay and Idempotency for copyable Windows and Unix configuration examples.
Capture accepts POST bodies up to 256 KiB, and stores at most 5,000 events. These limits are not exposed as environment variables. Oversized bodies return 413; full storage returns 507 without deleting old events. There is no retention/deletion UI yet.
Use pagination to inspect older events. The workbench filter applies to the loaded page, not a server-wide search.
Configuration implementation · Troubleshooting and Contributing