Skip to content

API and Configuration

Diego Gutierrez edited this page Sep 23, 2026 · 1 revision

Home · Previous: Replay and Idempotency · Next: Architecture and Security

API reference

Default base URL: http://127.0.0.1:8000. Interactive API documentation is available at /docs while the app is running.

All /api/* endpoints require Authorization: Bearer <admin token>. The inbox has its own private path token; do not confuse it with the administrator token.

Method Path Authentication Purpose
GET /health None Database connectivity and app version
POST /in/{inbox_token} Inbox path token Persist body and sanitized headers
GET /api/config Admin bearer Inbox path and named destinations
GET /api/events?limit=20&offset=0 Admin bearer Paginated events and aggregate counts
GET /api/events/{id} Admin bearer Body preview, exact base64 body and history
GET /api/events/{id}/body Admin bearer Download original body as attachment
POST /api/events/{id}/replay Admin bearer Record and perform one replay attempt

Replay request

POST /api/events/EVENT_ID/replay
Authorization: Bearer YOUR_ADMIN_TOKEN
Content-Type: application/json

{"target":"demo-success"}

Replace the placeholders using your local configuration and a captured event ID. Choose a target returned by /api/config. A caller cannot submit an arbitrary destination URL.

A 200 from the replay API means the attempt was recorded. Inspect its status and status_code to determine delivery outcome. A destination's 2xx does not prove its business operation succeeded.

Environment variables

Set variables in the shell that launches the app; restart after changing configuration.

Variable Default Meaning
WLAB_HOST 127.0.0.1 Bind address; keep local for this prototype
WLAB_PORT 8000 Listening port
WLAB_DATA_DIR data SQLite and generated token directory, relative to current working directory
WLAB_ADMIN_TOKEN Generated locally Administrator token, minimum 24 characters; choose a random value
WLAB_TARGETS {} JSON object mapping names to HTTP(S) URLs

When no administrator token is supplied, the app creates or reuses data/admin.token. With a custom data directory, read the token there instead. Do not commit tokens or data files.

Destination rules

  • Target names must be nonempty and cannot begin with demo-.
  • URLs must use HTTP or HTTPS and include a hostname.
  • URL credentials, query strings and fragments are rejected.
  • Redirect following and environment proxy settings are disabled.
  • Operator-controlled destinations are not a substitute for a hardened public egress gateway.

See Replay and Idempotency for copyable Windows and Unix configuration examples.

Fixed prototype limits

Capture accepts POST bodies up to 256 KiB, and stores at most 5,000 events. These limits are not exposed as environment variables. Oversized bodies return 413; full storage returns 507 without deleting old events. There is no retention/deletion UI yet.

Use pagination to inspect older events. The workbench filter applies to the loaded page, not a server-wide search.

Configuration implementation · Troubleshooting and Contributing