Tsunagu API reference
Everything goes through one GraphQL endpoint, POST /api/graphql, except for a handful of REST routes that stream bytes or handle auth directly.
GraphQL, by area
| Library | library, media, resolveMedia, setInLibrary, migrateMedia, syncChapters |
| Folders | folders, createFolder, renameFolder, deleteFolder, reorderFolder |
| Reading | readingProgress, markChapterRead, markChaptersRead, updateReadingProgress |
| Downloads | downloadQueue, enqueueDownload, dequeueDownload, retryDownload, reorderDownload |
| Extensions | repositories, availableExtensions, installExtension, uninstallExtension, updateExtension |
| Search | search, filterOptions, popularManga, latestUpdates, localSourceSearch |
| Trackers | trackers, trackerLogin, trackerLogout, bindTrack, pullTracker, trackerLibrary |
| Metadata | searchMetadata, applyMetadataMatch, refreshMetadataMatch |
| Server | serverSettings, updateServerSetting, contentFilterRules, storageInfo, databaseBackups |
REST routes
GET /content/{mediaId}/{chapterId}/pages/{n} | Byte-streams a page, from disk if downloaded or live otherwise |
GET /content/{mediaId}/{chapterId}/video | Streams anime video the same way |
GET /proxy/cover/{mediaId} | Cover image proxy and cache |
GET /api/auth/status | Whether a password is currently required |
POST /api/auth/login | Password login, issues a session token |
GET /api/tracker/mal/callback | MyAnimeList OAuth redirect target |
GET /healthz | Instant liveness check, independent of the sandbox |
/healthz, /api/auth/status, /api/auth/login, and everything under /api/tracker/ are exempt from the static API token check. Every other route requires it when api_token is set.