How to interact with Jeeves Server programmatically — for scripts, bots, AI assistants, and CI/CD pipelines.
Authentication for API Access
All API requests (except /health and /api/status) authenticate via ?key=<insider-key> URL parameter or session cookie.
Browser Auth Gate
When an unauthenticated browser hits a SPA route (/, /browse/*, /runner/*), the server returns a branded sign-in page instead of the SPA. The page shows an email login form as the primary action (when email auth is configured), with a "Sign in with Google" button below (when Google OAuth is also configured). When only Google auth is active, the Google button is shown alone. When only key auth is active, an API key required message is displayed. The page reflects instance branding (name, emoji) when configured. After successful sign-in, the user is redirected back to the originally requested page.
API routes continue returning JSON { error: 'Unauthorized' } for programmatic clients — the sign-in page only applies to browser-navigated SPA paths.
Get derived insider key (requires X-API-Key header with seed)
GET
/key?path=<path>
Compute outsider key for a path
POST
/api/share
Generate share link (path, expiry as epoch ms, depth, dirs)
POST
/api/util/share-for
Generate share link for a specific audience (insiders, enforceOutsiderPolicy)
POST
/api/rotate-key
Rotate an insider's key (invalidates all their outsider links)
Scopes and errors
Content routes (/api/path, /api/file, /api/raw, /api/export, /api/export-cache, /api/mermaid-export, /api/plantuml-export, /api/link-info) verify ?key= against the content path after the route prefix, so share keys work on all of them. For scoped identities:
Status
Body
When
400
{ "error": "Invalid path" }
The content path contains a .. segment
401
{ "error": "Unauthorized" }
No valid session or key
403
{ "error": "Path is outside your access scope" }
Authenticated, but the path is outside the identity's scopes
Directory listings and link info admit ancestors of in-scope paths (for navigation) and only list reachable entries; every other content route requires the path itself to be in scope. See Sharing → How scopes are enforced.