Tsunagu

API reference

Everything goes through one GraphQL endpoint, POST /api/graphql, except for a handful of REST routes that stream bytes or handle auth directly.

GraphQL, by area

Librarylibrary, media, resolveMedia, setInLibrary, migrateMedia, syncChapters
Foldersfolders, createFolder, renameFolder, deleteFolder, reorderFolder
ReadingreadingProgress, markChapterRead, markChaptersRead, updateReadingProgress
DownloadsdownloadQueue, enqueueDownload, dequeueDownload, retryDownload, reorderDownload
Extensionsrepositories, availableExtensions, installExtension, uninstallExtension, updateExtension
Searchsearch, filterOptions, popularManga, latestUpdates, localSourceSearch
Trackerstrackers, trackerLogin, trackerLogout, bindTrack, pullTracker, trackerLibrary
MetadatasearchMetadata, applyMetadataMatch, refreshMetadataMatch
ServerserverSettings, updateServerSetting, contentFilterRules, storageInfo, databaseBackups

REST routes

GET /content/{mediaId}/{chapterId}/pages/{n}Byte-streams a page, from disk if downloaded or live otherwise
GET /content/{mediaId}/{chapterId}/videoStreams anime video the same way
GET /proxy/cover/{mediaId}Cover image proxy and cache
GET /api/auth/statusWhether a password is currently required
POST /api/auth/loginPassword login, issues a session token
GET /api/tracker/mal/callbackMyAnimeList OAuth redirect target
GET /healthzInstant liveness check, independent of the sandbox
/healthz, /api/auth/status, /api/auth/login, and everything under /api/tracker/ are exempt from the static API token check. Every other route requires it when api_token is set.