API locale PowerOps

Une API HTTP sur 127.0.0.1 pour piloter profils, navigateurs, proxys, groupes et extensions. Compatible avec la surface de l'API locale AdsPower, implémentée sur les services de PowerOps.

v1.0.0

URL de base

http://127.0.0.1:50326

Authentification

L'authentification par jeton est active par défaut, et la clé est comparée en temps constant. Envoyez-la dans l'en-tête Authorization. Toutes les routes sauf GET /status l'exigent. PowerOps ne place jamais la clé dans une URL.

Authorization: Bearer YOUR_API_KEY

Enveloppe de réponse

Toutes les réponses utilisent la même enveloppe. Un code à 0 signifie succès ; -1 accompagne un message qui explique l'échec en clair.

{
  "code": 0,
  "msg": "success",
  "data": {}
}
{
  "code": -1,
  "msg": "Clear explanation of the failure",
  "data": {}
}

Erreurs

Les échecs renvoient HTTP 200 avec un code -1 par compatibilité, sauf lorsque le statut HTTP est la réponse : 401 pour une clé absente ou incorrecte, 404 pour une route inconnue, 413 pour un corps de plus de 256 Ko, et 429 en cas de dépassement de la limite de débit.

Opérations non prises en charge

Les routes qui existent dans la surface AdsPower mais n'ont pas d'implémentation honnête ici renvoient 501 avec une explication claire. Elles ne renvoient pas un succès fabriqué.

Sécurité

L'API écoute sur l'adresse de boucle locale, vérifie l'en-tête Host et n'envoie aucun en-tête CORS — une page web ne peut donc pas se servir de votre navigateur comme voie d'accès à votre machine. Les mots de passe de profil, les secrets 2FA et les mots de passe de proxy ne sont jamais renvoyés par une route de consultation, et les cookies ne proviennent que de leur propre route authentifiée.

Une première requête

curl -H "Authorization: Bearer YOUR_API_KEY" http://127.0.0.1:50326/status

Référence des routes

Générée à partir de la spécification que PowerOps sert lui-même, elle ne peut donc pas diverger de l'application.

Overview

Reachability.

GET/statusConnection statusno key

Check that the Local API is reachable. This is the only route that does not require a key: a caller has to be able to tell 'not running' from 'wrong key'.

Browser

Launching, stopping and inspecting real browser processes.

GET/api/v1/browser/startOpen browser

Launch a profile and return its live automation endpoint. `webdriver` and `ws.selenium` are absent: PowerOps ships no chromedriver, so there is no such address to return and inventing one would break a Selenium client at connect time.

NameInTypeDescription
user_idquerystringProfile id. Either this or serial_number.
serial_numberquerystringProfile number. user_id takes priority.
launch_argsquerystringJSON array of Chromium flags. Flags that would change profile isolation are refused.
headlessquerystring1 to launch headless. Not supported by PowerOps.
POST/api/v2/browser-profile/startOpen browser V2

As V1, with the profile named by `profile_id`/`profile_no` in a JSON body.

NameInTypeDescription
profile_idbodystringProfile id. Either this or profile_no.
profile_nobodystringProfile number. profile_id takes priority.
launch_argsbodyarrayChromium flags.
headlessbodystringNot supported by PowerOps.
GET/api/v1/browser/stopClose browser
NameInTypeDescription
user_idquerystringProfile id.
serial_numberquerystringProfile number.
POST/api/v2/browser-profile/stopClose browser V2
NameInTypeDescription
profile_idbodystringProfile id.
profile_nobodystringProfile number.
GET/api/v1/browser/activeCheck browser status

`status` is `Active` or `Inactive`, read from the real process. When it is Active the automation endpoint is probed live before it is reported.

NameInTypeDescription
user_idquerystringProfile id.
serial_numberquerystringProfile number.
GET/api/v1/browser/local-activeActive browsers on this device

Every profile in the open workspace whose browser is running, each with its live endpoint. A profile whose endpoint no longer answers is omitted rather than listed with a stale port.

Proxy

The proxy library. Passwords are never returned.

POST/api/v2/proxy-list/createAdd proxy
NameInTypeDescription
type *bodystringhttp, https or socks5.
host *bodystringProxy host.
port *bodystringProxy port.
userbodystringProxy username.
passwordbodystringProxy password. Stored in the credential store and never returned.
remarkbodystringLabel.
POST/api/v2/proxy-list/updateUpdate proxy
NameInTypeDescription
proxy_id *bodystringProxy id.
typebodystringhttp, https or socks5.
hostbodystringProxy host.
portbodystringProxy port.
userbodystringProxy username.
passwordbodystringProxy password.
remarkbodystringLabel.
POST/api/v2/proxy-list/deleteDelete proxy
NameInTypeDescription
proxy_id *bodyarrayProxy ids. At most 100.
POST/api/v2/proxy-list/listQuery proxy

`password` is always empty: a stored proxy password never leaves the credential store.

NameInTypeDescription
proxy_idbodyarrayFilter by proxy ids.
pagebodyintegerPage number, from 1.
limitbodyintegerPage size, 1–200.

Groups

Profile groups.

POST/api/v1/group/createNew group
NameInTypeDescription
group_name *bodystringGroup name. Must be unique.
remarkbodystringNotes.
POST/api/v1/group/updateEdit group
NameInTypeDescription
group_id *bodystringGroup id.
group_name *bodystringNew name.
remarkbodystringNotes.
GET/api/v1/group/listQuery group
NameInTypeDescription
group_namequerystringFilter by name, case-insensitive substring.
pagequerystringPage number, from 1.
page_sizequerystringPage size, up to 2000.

Extensions

Installed extensions, reported as categories.

GET/api/v1/application/listCategory list

PowerOps has no separate application-category entity: an extension IS the unit it assigns to profiles, so each installed extension is reported as one category.

NameInTypeDescription
pagequerystringPage number.
page_sizequerystringPage size, up to 100.
GET/api/v2/category/listCategory list V2
NameInTypeDescription
category_idquerystringFilter by id.
pagequerystringPage number.
limitquerystringPage size, 1–100.

Profiles

Profile lifecycle. Credentials are never returned.

POST/api/v1/user/createNew profile

PowerOps generates a coherent identity from a region preset, so `fingerprint_config` keys it has no knob for are listed back in `ignored_fingerprint_fields` rather than accepted and dropped.

NameInTypeDescription
namebodystringProfile name.
group_id *bodystringGroup to place the profile in. 0 or absent means ungrouped.
remarkbodystringNotes.
domain_namebodystringPlatform domain, e.g. facebook.com.
user_proxy_configbodyobjectProxy configuration. proxy_soft must be "other" or "no_proxy".
fingerprint_config *bodyobjectFingerprint inputs. Unapplied keys are reported in the response.
usernamebodystringPlatform account address.
passwordbodystringPlatform account password. Stored in the credential store, never returned.
POST/api/v2/browser-profile/createNew profile V2
NameInTypeDescription
namebodystringProfile name.
group_id *bodystringGroup to place the profile in. 0 or absent means ungrouped.
remarkbodystringNotes.
platformbodystringPlatform domain, e.g. facebook.com.
user_proxy_configbodyobjectProxy configuration. proxy_soft must be "other" or "no_proxy".
fingerprint_config *bodyobjectFingerprint inputs. Unapplied keys are reported in the response.
usernamebodystringPlatform account address.
passwordbodystringPlatform account password. Stored in the credential store, never returned.
POST/api/v1/user/updateUpdate profile info
NameInTypeDescription
user_id *bodystringProfile id.
namebodystringProfile name.
remarkbodystringNotes.
user_proxy_configbodyobjectProxy configuration.
POST/api/v2/browser-profile/updateUpdate profile info V2
NameInTypeDescription
profile_id *bodystringProfile id.
namebodystringProfile name.
remarkbodystringNotes.
user_proxy_configbodyobjectProxy configuration.
GET/api/v1/user/listQuery profile

`password` is always empty and `username` is masked. The desktop shows the real values on a screen an operator is looking at; an HTTP response is a different boundary.

NameInTypeDescription
group_idquerystringFilter by group.
user_idquerystringFilter to one profile.
serial_numberquerystringFilter to one profile by number.
pagequerystringPage number, from 1.
page_sizequerystringPage size, up to 100.
POST/api/v2/browser-profile/listQuery profile V2
NameInTypeDescription
group_idbodystringFilter by group.
profile_idbodyarrayFilter to these profile ids.
profile_nobodyarrayFilter to these profile numbers.
pagebodyintegerPage number, from 1.
limitbodyintegerPage size, 1–100.
POST/api/v1/user/deleteDelete profile

Permanent. The profile row, its browsing data and every credential it stored are removed.

NameInTypeDescription
user_ids *bodyarrayProfile ids. At most 100.
POST/api/v2/browser-profile/deleteDelete profile V2
NameInTypeDescription
profile_id *bodyarrayProfile ids. At most 100.
POST/api/v1/user/regroupMove profile
NameInTypeDescription
user_ids *bodyarrayProfile ids to move.
group_id *bodystringDestination group. 0 means ungrouped.
POST/api/v1/user/delete-cacheDelete cache

Clears every cache category for the named profiles. Refuses while a browser is open: Chromium holds these files and deleting them under a live process corrupts the profile.

NameInTypeDescription
user_ids *bodyarrayProfile ids.
POST/api/v2/browser-profile/delete-cacheDelete cache V2
NameInTypeDescription
profile_id *bodyarrayProfile ids.
type *bodyarrayCache categories: image_file, local_storage, indexeddb, extension_cache, cookie, history.
GET/api/v2/browser-profile/cookiesQuery profile cookies

A SEPARATE, explicitly authenticated endpoint. Cookie values are a credential — they sign in as the account — so they are never included in any query response and are only returned here, to a caller holding the API key.

NameInTypeDescription
profile_idquerystringProfile id.
profile_noquerystringProfile number.

Documentation interactive

Pendant que PowerOps fonctionne, la même spécification est servie sur votre machine à l'adresse http://127.0.0.1:50326/docs, où vous pouvez envoyer de vraies requêtes.

Il n'y a pas de testeur de requêtes sur cette page. Envoyer une requête depuis ce site vers votre propre 127.0.0.1 correspond exactement à une attaque par réattachement DNS, et l'API locale de PowerOps la refuse par conception. Le testeur se trouve sur le /docs local, sur la même origine que l'API, où votre clé ne traverse aucun réseau.