/statusConnection statusno keyCheck that the Local API is reachable. This is the only route that does not require a key: a caller has to be able to tell 'not running' from 'wrong key'.
An HTTP API on 127.0.0.1 for driving profiles, browsers, proxies, groups and extensions. Compatible with the AdsPower Local API surface, implemented against PowerOps' own services.
v1.0.0
http://127.0.0.1:50326Bearer authentication is on by default, and the key is compared in constant time. Send it in the Authorization header. Every route except GET /status requires it. PowerOps never puts the key in a URL.
Authorization: Bearer YOUR_API_KEYEvery response uses the same envelope. A code of 0 means success; -1 carries a message that explains the failure in plain words.
{
"code": 0,
"msg": "success",
"data": {}
}{
"code": -1,
"msg": "Clear explanation of the failure",
"data": {}
}Failures return HTTP 200 with code -1 for compatibility, except where the HTTP status is the answer: 401 for a missing or wrong key, 404 for an unknown route, 413 for a body over 256 KB, and 429 when the rate limit is exceeded.
Endpoints that exist in the AdsPower surface but have no honest implementation here return 501 with a plain explanation. They do not return a fabricated success.
The API binds the loopback address, checks the Host header, and sends no CORS headers — so a web page cannot use your browser as a route into your own machine. Profile passwords, 2FA secrets and proxy passwords are never returned by a query endpoint, and cookies come only from their own authenticated endpoint.
curl -H "Authorization: Bearer YOUR_API_KEY" http://127.0.0.1:50326/statusGenerated from the specification PowerOps itself serves, so it cannot drift from the application.
Reachability.
/statusConnection statusno keyCheck that the Local API is reachable. This is the only route that does not require a key: a caller has to be able to tell 'not running' from 'wrong key'.
Launching, stopping and inspecting real browser processes.
/api/v1/browser/startOpen browserLaunch a profile and return its live automation endpoint. `webdriver` and `ws.selenium` are absent: PowerOps ships no chromedriver, so there is no such address to return and inventing one would break a Selenium client at connect time.
| Name | In | Type | Description |
|---|---|---|---|
| user_id | query | string | Profile id. Either this or serial_number. |
| serial_number | query | string | Profile number. user_id takes priority. |
| launch_args | query | string | JSON array of Chromium flags. Flags that would change profile isolation are refused. |
| headless | query | string | 1 to launch headless. Not supported by PowerOps. |
/api/v2/browser-profile/startOpen browser V2As V1, with the profile named by `profile_id`/`profile_no` in a JSON body.
| Name | In | Type | Description |
|---|---|---|---|
| profile_id | body | string | Profile id. Either this or profile_no. |
| profile_no | body | string | Profile number. profile_id takes priority. |
| launch_args | body | array | Chromium flags. |
| headless | body | string | Not supported by PowerOps. |
/api/v1/browser/stopClose browser| Name | In | Type | Description |
|---|---|---|---|
| user_id | query | string | Profile id. |
| serial_number | query | string | Profile number. |
/api/v2/browser-profile/stopClose browser V2| Name | In | Type | Description |
|---|---|---|---|
| profile_id | body | string | Profile id. |
| profile_no | body | string | Profile number. |
/api/v1/browser/activeCheck browser status`status` is `Active` or `Inactive`, read from the real process. When it is Active the automation endpoint is probed live before it is reported.
| Name | In | Type | Description |
|---|---|---|---|
| user_id | query | string | Profile id. |
| serial_number | query | string | Profile number. |
/api/v1/browser/local-activeActive browsers on this deviceEvery profile in the open workspace whose browser is running, each with its live endpoint. A profile whose endpoint no longer answers is omitted rather than listed with a stale port.
The proxy library. Passwords are never returned.
/api/v2/proxy-list/createAdd proxy| Name | In | Type | Description |
|---|---|---|---|
| type * | body | string | http, https or socks5. |
| host * | body | string | Proxy host. |
| port * | body | string | Proxy port. |
| user | body | string | Proxy username. |
| password | body | string | Proxy password. Stored in the credential store and never returned. |
| remark | body | string | Label. |
/api/v2/proxy-list/updateUpdate proxy| Name | In | Type | Description |
|---|---|---|---|
| proxy_id * | body | string | Proxy id. |
| type | body | string | http, https or socks5. |
| host | body | string | Proxy host. |
| port | body | string | Proxy port. |
| user | body | string | Proxy username. |
| password | body | string | Proxy password. |
| remark | body | string | Label. |
/api/v2/proxy-list/deleteDelete proxy| Name | In | Type | Description |
|---|---|---|---|
| proxy_id * | body | array | Proxy ids. At most 100. |
/api/v2/proxy-list/listQuery proxy`password` is always empty: a stored proxy password never leaves the credential store.
| Name | In | Type | Description |
|---|---|---|---|
| proxy_id | body | array | Filter by proxy ids. |
| page | body | integer | Page number, from 1. |
| limit | body | integer | Page size, 1–200. |
Profile groups.
/api/v1/group/createNew group| Name | In | Type | Description |
|---|---|---|---|
| group_name * | body | string | Group name. Must be unique. |
| remark | body | string | Notes. |
/api/v1/group/updateEdit group| Name | In | Type | Description |
|---|---|---|---|
| group_id * | body | string | Group id. |
| group_name * | body | string | New name. |
| remark | body | string | Notes. |
/api/v1/group/listQuery group| Name | In | Type | Description |
|---|---|---|---|
| group_name | query | string | Filter by name, case-insensitive substring. |
| page | query | string | Page number, from 1. |
| page_size | query | string | Page size, up to 2000. |
Installed extensions, reported as categories.
/api/v1/application/listCategory listPowerOps has no separate application-category entity: an extension IS the unit it assigns to profiles, so each installed extension is reported as one category.
| Name | In | Type | Description |
|---|---|---|---|
| page | query | string | Page number. |
| page_size | query | string | Page size, up to 100. |
/api/v2/category/listCategory list V2| Name | In | Type | Description |
|---|---|---|---|
| category_id | query | string | Filter by id. |
| page | query | string | Page number. |
| limit | query | string | Page size, 1–100. |
Profile lifecycle. Credentials are never returned.
/api/v1/user/createNew profilePowerOps generates a coherent identity from a region preset, so `fingerprint_config` keys it has no knob for are listed back in `ignored_fingerprint_fields` rather than accepted and dropped.
| Name | In | Type | Description |
|---|---|---|---|
| name | body | string | Profile name. |
| group_id * | body | string | Group to place the profile in. 0 or absent means ungrouped. |
| remark | body | string | Notes. |
| domain_name | body | string | Platform domain, e.g. facebook.com. |
| user_proxy_config | body | object | Proxy configuration. proxy_soft must be "other" or "no_proxy". |
| fingerprint_config * | body | object | Fingerprint inputs. Unapplied keys are reported in the response. |
| username | body | string | Platform account address. |
| password | body | string | Platform account password. Stored in the credential store, never returned. |
/api/v2/browser-profile/createNew profile V2| Name | In | Type | Description |
|---|---|---|---|
| name | body | string | Profile name. |
| group_id * | body | string | Group to place the profile in. 0 or absent means ungrouped. |
| remark | body | string | Notes. |
| platform | body | string | Platform domain, e.g. facebook.com. |
| user_proxy_config | body | object | Proxy configuration. proxy_soft must be "other" or "no_proxy". |
| fingerprint_config * | body | object | Fingerprint inputs. Unapplied keys are reported in the response. |
| username | body | string | Platform account address. |
| password | body | string | Platform account password. Stored in the credential store, never returned. |
/api/v1/user/updateUpdate profile info| Name | In | Type | Description |
|---|---|---|---|
| user_id * | body | string | Profile id. |
| name | body | string | Profile name. |
| remark | body | string | Notes. |
| user_proxy_config | body | object | Proxy configuration. |
/api/v2/browser-profile/updateUpdate profile info V2| Name | In | Type | Description |
|---|---|---|---|
| profile_id * | body | string | Profile id. |
| name | body | string | Profile name. |
| remark | body | string | Notes. |
| user_proxy_config | body | object | Proxy configuration. |
/api/v1/user/listQuery profile`password` is always empty and `username` is masked. The desktop shows the real values on a screen an operator is looking at; an HTTP response is a different boundary.
| Name | In | Type | Description |
|---|---|---|---|
| group_id | query | string | Filter by group. |
| user_id | query | string | Filter to one profile. |
| serial_number | query | string | Filter to one profile by number. |
| page | query | string | Page number, from 1. |
| page_size | query | string | Page size, up to 100. |
/api/v2/browser-profile/listQuery profile V2| Name | In | Type | Description |
|---|---|---|---|
| group_id | body | string | Filter by group. |
| profile_id | body | array | Filter to these profile ids. |
| profile_no | body | array | Filter to these profile numbers. |
| page | body | integer | Page number, from 1. |
| limit | body | integer | Page size, 1–100. |
/api/v1/user/deleteDelete profilePermanent. The profile row, its browsing data and every credential it stored are removed.
| Name | In | Type | Description |
|---|---|---|---|
| user_ids * | body | array | Profile ids. At most 100. |
/api/v2/browser-profile/deleteDelete profile V2| Name | In | Type | Description |
|---|---|---|---|
| profile_id * | body | array | Profile ids. At most 100. |
/api/v1/user/regroupMove profile| Name | In | Type | Description |
|---|---|---|---|
| user_ids * | body | array | Profile ids to move. |
| group_id * | body | string | Destination group. 0 means ungrouped. |
/api/v1/user/delete-cacheDelete cacheClears every cache category for the named profiles. Refuses while a browser is open: Chromium holds these files and deleting them under a live process corrupts the profile.
| Name | In | Type | Description |
|---|---|---|---|
| user_ids * | body | array | Profile ids. |
/api/v2/browser-profile/delete-cacheDelete cache V2| Name | In | Type | Description |
|---|---|---|---|
| profile_id * | body | array | Profile ids. |
| type * | body | array | Cache categories: image_file, local_storage, indexeddb, extension_cache, cookie, history. |
/api/v2/browser-profile/cookiesQuery profile cookiesA SEPARATE, explicitly authenticated endpoint. Cookie values are a credential — they sign in as the account — so they are never included in any query response and are only returned here, to a caller holding the API key.
| Name | In | Type | Description |
|---|---|---|---|
| profile_id | query | string | Profile id. |
| profile_no | query | string | Profile number. |
While PowerOps is running, the same specification is served on your own machine at http://127.0.0.1:50326/docs, where you can send real requests.
There is no request tester on this page. Sending a request from this website to your own 127.0.0.1 is the shape of a DNS-rebinding attack, and the PowerOps Local API refuses it by design. The tester lives at the local /docs, on the same origin as the API, where your key never crosses a network.