PowerOps Local API

An HTTP API on 127.0.0.1 for driving profiles, browsers, proxies, groups and extensions. Compatible with the AdsPower Local API surface, implemented against PowerOps' own services.

v1.0.0

Base URL

http://127.0.0.1:50326

Authentication

Bearer authentication is on by default, and the key is compared in constant time. Send it in the Authorization header. Every route except GET /status requires it. PowerOps never puts the key in a URL.

Authorization: Bearer YOUR_API_KEY

Response envelope

Every response uses the same envelope. A code of 0 means success; -1 carries a message that explains the failure in plain words.

{
  "code": 0,
  "msg": "success",
  "data": {}
}
{
  "code": -1,
  "msg": "Clear explanation of the failure",
  "data": {}
}

Errors

Failures return HTTP 200 with code -1 for compatibility, except where the HTTP status is the answer: 401 for a missing or wrong key, 404 for an unknown route, 413 for a body over 256 KB, and 429 when the rate limit is exceeded.

Unsupported operations

Endpoints that exist in the AdsPower surface but have no honest implementation here return 501 with a plain explanation. They do not return a fabricated success.

Security

The API binds the loopback address, checks the Host header, and sends no CORS headers — so a web page cannot use your browser as a route into your own machine. Profile passwords, 2FA secrets and proxy passwords are never returned by a query endpoint, and cookies come only from their own authenticated endpoint.

A first request

curl -H "Authorization: Bearer YOUR_API_KEY" http://127.0.0.1:50326/status

Endpoint reference

Generated from the specification PowerOps itself serves, so it cannot drift from the application.

Overview

Reachability.

GET/statusConnection statusno key

Check that the Local API is reachable. This is the only route that does not require a key: a caller has to be able to tell 'not running' from 'wrong key'.

Browser

Launching, stopping and inspecting real browser processes.

GET/api/v1/browser/startOpen browser

Launch a profile and return its live automation endpoint. `webdriver` and `ws.selenium` are absent: PowerOps ships no chromedriver, so there is no such address to return and inventing one would break a Selenium client at connect time.

NameInTypeDescription
user_idquerystringProfile id. Either this or serial_number.
serial_numberquerystringProfile number. user_id takes priority.
launch_argsquerystringJSON array of Chromium flags. Flags that would change profile isolation are refused.
headlessquerystring1 to launch headless. Not supported by PowerOps.
POST/api/v2/browser-profile/startOpen browser V2

As V1, with the profile named by `profile_id`/`profile_no` in a JSON body.

NameInTypeDescription
profile_idbodystringProfile id. Either this or profile_no.
profile_nobodystringProfile number. profile_id takes priority.
launch_argsbodyarrayChromium flags.
headlessbodystringNot supported by PowerOps.
GET/api/v1/browser/stopClose browser
NameInTypeDescription
user_idquerystringProfile id.
serial_numberquerystringProfile number.
POST/api/v2/browser-profile/stopClose browser V2
NameInTypeDescription
profile_idbodystringProfile id.
profile_nobodystringProfile number.
GET/api/v1/browser/activeCheck browser status

`status` is `Active` or `Inactive`, read from the real process. When it is Active the automation endpoint is probed live before it is reported.

NameInTypeDescription
user_idquerystringProfile id.
serial_numberquerystringProfile number.
GET/api/v1/browser/local-activeActive browsers on this device

Every profile in the open workspace whose browser is running, each with its live endpoint. A profile whose endpoint no longer answers is omitted rather than listed with a stale port.

Proxy

The proxy library. Passwords are never returned.

POST/api/v2/proxy-list/createAdd proxy
NameInTypeDescription
type *bodystringhttp, https or socks5.
host *bodystringProxy host.
port *bodystringProxy port.
userbodystringProxy username.
passwordbodystringProxy password. Stored in the credential store and never returned.
remarkbodystringLabel.
POST/api/v2/proxy-list/updateUpdate proxy
NameInTypeDescription
proxy_id *bodystringProxy id.
typebodystringhttp, https or socks5.
hostbodystringProxy host.
portbodystringProxy port.
userbodystringProxy username.
passwordbodystringProxy password.
remarkbodystringLabel.
POST/api/v2/proxy-list/deleteDelete proxy
NameInTypeDescription
proxy_id *bodyarrayProxy ids. At most 100.
POST/api/v2/proxy-list/listQuery proxy

`password` is always empty: a stored proxy password never leaves the credential store.

NameInTypeDescription
proxy_idbodyarrayFilter by proxy ids.
pagebodyintegerPage number, from 1.
limitbodyintegerPage size, 1–200.

Groups

Profile groups.

POST/api/v1/group/createNew group
NameInTypeDescription
group_name *bodystringGroup name. Must be unique.
remarkbodystringNotes.
POST/api/v1/group/updateEdit group
NameInTypeDescription
group_id *bodystringGroup id.
group_name *bodystringNew name.
remarkbodystringNotes.
GET/api/v1/group/listQuery group
NameInTypeDescription
group_namequerystringFilter by name, case-insensitive substring.
pagequerystringPage number, from 1.
page_sizequerystringPage size, up to 2000.

Extensions

Installed extensions, reported as categories.

GET/api/v1/application/listCategory list

PowerOps has no separate application-category entity: an extension IS the unit it assigns to profiles, so each installed extension is reported as one category.

NameInTypeDescription
pagequerystringPage number.
page_sizequerystringPage size, up to 100.
GET/api/v2/category/listCategory list V2
NameInTypeDescription
category_idquerystringFilter by id.
pagequerystringPage number.
limitquerystringPage size, 1–100.

Profiles

Profile lifecycle. Credentials are never returned.

POST/api/v1/user/createNew profile

PowerOps generates a coherent identity from a region preset, so `fingerprint_config` keys it has no knob for are listed back in `ignored_fingerprint_fields` rather than accepted and dropped.

NameInTypeDescription
namebodystringProfile name.
group_id *bodystringGroup to place the profile in. 0 or absent means ungrouped.
remarkbodystringNotes.
domain_namebodystringPlatform domain, e.g. facebook.com.
user_proxy_configbodyobjectProxy configuration. proxy_soft must be "other" or "no_proxy".
fingerprint_config *bodyobjectFingerprint inputs. Unapplied keys are reported in the response.
usernamebodystringPlatform account address.
passwordbodystringPlatform account password. Stored in the credential store, never returned.
POST/api/v2/browser-profile/createNew profile V2
NameInTypeDescription
namebodystringProfile name.
group_id *bodystringGroup to place the profile in. 0 or absent means ungrouped.
remarkbodystringNotes.
platformbodystringPlatform domain, e.g. facebook.com.
user_proxy_configbodyobjectProxy configuration. proxy_soft must be "other" or "no_proxy".
fingerprint_config *bodyobjectFingerprint inputs. Unapplied keys are reported in the response.
usernamebodystringPlatform account address.
passwordbodystringPlatform account password. Stored in the credential store, never returned.
POST/api/v1/user/updateUpdate profile info
NameInTypeDescription
user_id *bodystringProfile id.
namebodystringProfile name.
remarkbodystringNotes.
user_proxy_configbodyobjectProxy configuration.
POST/api/v2/browser-profile/updateUpdate profile info V2
NameInTypeDescription
profile_id *bodystringProfile id.
namebodystringProfile name.
remarkbodystringNotes.
user_proxy_configbodyobjectProxy configuration.
GET/api/v1/user/listQuery profile

`password` is always empty and `username` is masked. The desktop shows the real values on a screen an operator is looking at; an HTTP response is a different boundary.

NameInTypeDescription
group_idquerystringFilter by group.
user_idquerystringFilter to one profile.
serial_numberquerystringFilter to one profile by number.
pagequerystringPage number, from 1.
page_sizequerystringPage size, up to 100.
POST/api/v2/browser-profile/listQuery profile V2
NameInTypeDescription
group_idbodystringFilter by group.
profile_idbodyarrayFilter to these profile ids.
profile_nobodyarrayFilter to these profile numbers.
pagebodyintegerPage number, from 1.
limitbodyintegerPage size, 1–100.
POST/api/v1/user/deleteDelete profile

Permanent. The profile row, its browsing data and every credential it stored are removed.

NameInTypeDescription
user_ids *bodyarrayProfile ids. At most 100.
POST/api/v2/browser-profile/deleteDelete profile V2
NameInTypeDescription
profile_id *bodyarrayProfile ids. At most 100.
POST/api/v1/user/regroupMove profile
NameInTypeDescription
user_ids *bodyarrayProfile ids to move.
group_id *bodystringDestination group. 0 means ungrouped.
POST/api/v1/user/delete-cacheDelete cache

Clears every cache category for the named profiles. Refuses while a browser is open: Chromium holds these files and deleting them under a live process corrupts the profile.

NameInTypeDescription
user_ids *bodyarrayProfile ids.
POST/api/v2/browser-profile/delete-cacheDelete cache V2
NameInTypeDescription
profile_id *bodyarrayProfile ids.
type *bodyarrayCache categories: image_file, local_storage, indexeddb, extension_cache, cookie, history.
GET/api/v2/browser-profile/cookiesQuery profile cookies

A SEPARATE, explicitly authenticated endpoint. Cookie values are a credential — they sign in as the account — so they are never included in any query response and are only returned here, to a caller holding the API key.

NameInTypeDescription
profile_idquerystringProfile id.
profile_noquerystringProfile number.

Interactive documentation

While PowerOps is running, the same specification is served on your own machine at http://127.0.0.1:50326/docs, where you can send real requests.

There is no request tester on this page. Sending a request from this website to your own 127.0.0.1 is the shape of a DNS-rebinding attack, and the PowerOps Local API refuses it by design. The tester lives at the local /docs, on the same origin as the API, where your key never crosses a network.