XFlow Platform API (5.3.5.0)

Download OpenAPI specification:

XFlow Platform API documentation

Users

Get user list

Gets the list of users

Authorizations:
OAuth2Password

Responses

Response samples

Content type
application/json
{
  • "message": "string",
  • "user_count": 0,
  • "users": [
    ]
}

Add user

Adds a new user

Authorizations:
OAuth2Password
Request Body schema: application/json
required

User

auth_provider
string

Which authentication source owns this account. "" means a native local account, which makes every document that already exists correct with no migration: absent reads as empty. Otherwise the config.env provider id. See MIXED_AUTH_SSO.md section 3.

auth_subject
string

The provider's immutable subject ("sub") for this account, bound on the first federated sign-in. SERVER-SET: never accepted from a client payload, and never written by an admin's edit except to clear it (see UserAccountUpdate).

Array of objects (data.CameraControlGroupPermission)

List of camera group permissions for the user.

disabled
boolean

Disabled refuses the account's sign-ins (password and provider alike) and, through the session snapshot the auth middleware consults on every request, the tokens it already holds. Absent on pre-existing documents = false.

email
string

Email of the user.

first_name
string

First name of the user.

last_login
string

Date and time of the user's most recent successful login (zero if never).

last_name
string

Last name of the user.

last_updated
string

Date and time the user was last updated.

organization
string

Organization of the user.

password
string

Password of the user.

phone
string

Phone number of the user.

recordings_access
boolean

Whether a user-role account may access Recordings (playback + schedule). Admins and super users always may; absent on pre-existing docs = false (no access until granted).

role
string
Enum: "admin" "super_user" "user" "api" "guest"

Role of the user.

session_lifetime_mins
integer

SessionLifetimeMins overrides the deployment's JWT_EXPIRATION_MINS for this account: 0 = the deployment default, SESSION_LIFETIME_UNLIMITED = tokens that never expire, otherwise minutes (at least SESSION_LIFETIME_MIN_MINS). Local accounts only: a federated account keeps the deployment default, so the provider's users never hold a longer session than the deployment chose. Absent on pre-existing documents = 0.

stream_groups
Array of strings

List of stream groups for the user.

title
string

Title of the user.

username
string

Username of the user.

Responses

Request samples

Content type
application/json
{
  • "auth_provider": "string",
  • "auth_subject": "string",
  • "camera_group_permissions": [
    ],
  • "disabled": true,
  • "email": "string",
  • "first_name": "string",
  • "last_login": "string",
  • "last_name": "string",
  • "last_updated": "string",
  • "organization": "string",
  • "password": "string",
  • "phone": "string",
  • "recordings_access": true,
  • "role": "admin",
  • "session_lifetime_mins": 0,
  • "stream_groups": [
    ],
  • "title": "string",
  • "username": "string"
}

Response samples

Content type
application/json
{
  • "message": "string",
  • "user": {
    }
}

Add and login new admin user

Adds and logs in new admin user

Request Body schema: application/json
required

Login

grant_type
string

Type of grant. Must be 'password'.

key
string

XFlow instance key provided by Optima DTS.

password
string

Password of the user.

username
string

Username of the user.

Responses

Request samples

Content type
application/json
{
  • "grant_type": "string",
  • "key": "string",
  • "password": "string",
  • "username": "string"
}

Response samples

Content type
application/json
{
  • "access_token": "string",
  • "expires_in": 0,
  • "message": "string",
  • "token_type": "string",
  • "userId": "string"
}

Delete user

Deletes the user

Authorizations:
OAuth2Password
path Parameters
username
required
string

Username

Responses

Response samples

Content type
application/json
"string"

End user sessions

Ends every session of the user (sign out everywhere): each token the account holds is refused from now on, and the account signs in afresh.

Authorizations:
OAuth2Password
path Parameters
username
required
string

Username

Responses

Response samples

Content type
application/json
"string"

Login user

Logs in the user using OAuth2 password flow. Expects form data: username, password, grant_type, or data.LoginRequest JSON object body.

Request Body schema: application/x-www-form-urlencoded
username
string

Username

password
string

Password

grant_type
string

OAuth2 grant type 'password'

Responses

Response samples

Content type
application/json
{
  • "access_token": "string",
  • "expires_in": 0,
  • "message": "string",
  • "token_type": "string",
  • "userId": "string"
}

Send credentials / password-setup link to a user

Emails a user their username and a secure, single-use link to set their password, so an admin can send or resend login credentials from the users page. Admin-only. Requires the target user to have an email address and the deployment mail to be configured. Reuses the password-reset token + confirm flow, so it works regardless of the self-service reset switch.

Authorizations:
OAuth2Password

Responses

Response samples

Content type
application/json
{
  • "property1": "string",
  • "property2": "string"
}

Update user

Updates a user

Authorizations:
OAuth2Password
path Parameters
username
required
string

Username

Request Body schema: application/json
required

User

auth_provider
string

Which authentication source owns this account. "" means a native local account, which makes every document that already exists correct with no migration: absent reads as empty. Otherwise the config.env provider id. See MIXED_AUTH_SSO.md section 3.

auth_subject
string

The provider's immutable subject ("sub") for this account, bound on the first federated sign-in. SERVER-SET: never accepted from a client payload, and never written by an admin's edit except to clear it (see UserAccountUpdate).

Array of objects (data.CameraControlGroupPermission)

List of camera group permissions for the user.

disabled
boolean

Disabled refuses the account's sign-ins (password and provider alike) and, through the session snapshot the auth middleware consults on every request, the tokens it already holds. Absent on pre-existing documents = false.

email
string

Email of the user.

first_name
string

First name of the user.

last_login
string

Date and time of the user's most recent successful login (zero if never).

last_name
string

Last name of the user.

last_updated
string

Date and time the user was last updated.

organization
string

Organization of the user.

password
string

Password of the user.

phone
string

Phone number of the user.

recordings_access
boolean

Whether a user-role account may access Recordings (playback + schedule). Admins and super users always may; absent on pre-existing docs = false (no access until granted).

role
string
Enum: "admin" "super_user" "user" "api" "guest"

Role of the user.

session_lifetime_mins
integer

SessionLifetimeMins overrides the deployment's JWT_EXPIRATION_MINS for this account: 0 = the deployment default, SESSION_LIFETIME_UNLIMITED = tokens that never expire, otherwise minutes (at least SESSION_LIFETIME_MIN_MINS). Local accounts only: a federated account keeps the deployment default, so the provider's users never hold a longer session than the deployment chose. Absent on pre-existing documents = 0.

stream_groups
Array of strings

List of stream groups for the user.

title
string

Title of the user.

username
string

Username of the user.

Responses

Request samples

Content type
application/json
{
  • "auth_provider": "string",
  • "auth_subject": "string",
  • "camera_group_permissions": [
    ],
  • "disabled": true,
  • "email": "string",
  • "first_name": "string",
  • "last_login": "string",
  • "last_name": "string",
  • "last_updated": "string",
  • "organization": "string",
  • "password": "string",
  • "phone": "string",
  • "recordings_access": true,
  • "role": "admin",
  • "session_lifetime_mins": 0,
  • "stream_groups": [
    ],
  • "title": "string",
  • "username": "string"
}

Response samples

Content type
application/json
{
  • "message": "string",
  • "user": {
    }
}

Update user password

Updates a user password

Authorizations:
OAuth2Password
Request Body schema: application/json
required

Update Password Request

new_password
string

New password of the user.

old_password
string

Old password of the user.

Responses

Request samples

Content type
application/json
{
  • "new_password": "string",
  • "old_password": "string"
}

Response samples

Content type
application/json
"string"

Cluster Configuration

Get cluster configuration

Gets current cluster configuration

Authorizations:
OAuth2Password

Responses

Response samples

Content type
application/json
{
  • "clusterConfig": {
    },
  • "message": "string"
}

Get ASN blacklist status

Gets the state of the ASN rows' ranges (fetched from ODTS_MANAGER), the resolved prefix set, and each engine's progress towards it

Authorizations:
OAuth2Password

Responses

Response samples

Content type
application/json
{
  • "asns": [
    ],
  • "engines": [
    ],
  • "generated": "string",
  • "hash": "string",
  • "v4_count": 0,
  • "v6_count": 0
}

Set cluster configuration

Sets the current cluster configuration

Authorizations:
OAuth2Password
Request Body schema: application/json
required

Cluster configuration

admin_access_restriction_enabled
boolean

Manager Settings — admin-role access IP restriction. When enabled, only clients whose IP/CIDR is listed in AdminIpWhitelist (or loopback) may authenticate as, or make API calls as, an admin. Unlike the per-protocol stream whitelists, an empty list WHILE ENABLED denies all non-loopback admin access (the whitelist is the authoritative admin-IP gate, not an additive filter). Fleet-managed (part of ManagedClusterConfig) since 2026-08-30.

Array of objects (data.IpListItem)

Admin-role access IP whitelist. Applies only when admin_access_restriction_enabled is true.

Array of objects (data.OriginListItem)

List of allowed HTTP origins / referers.

Array of objects (data.IpListItem)

Client IPs blacklisted by the auto-blacklister. Site-local and server-owned: written only by targeted $push/$pull, never by the full config save or a managed push.

auto_blacklist_duration_hours
integer

Duration in hours for which a client IP is automatically blacklisted. A value of 0 results in the client IP being blacklisted indefinitely (until manually removed from the blacklist).

auto_blacklist_hls
boolean

Enable the automatic blacklisting of client IPs that concurrently accessing more than auto_blacklist_hls_max_connections unique HLS streams.

auto_blacklist_hls_max_connections
integer

Maximum number of unique HLS streams that can be concurrently accessed before a given client IP is automatically blacklisted.

Array of objects (data.IpListItem)

IP exemptions from automatic blacklisting. If set to null, no IPs are exempted from automatic blacklisting.

auto_blacklist_llhls
boolean

Enable the automatic blacklisting of client IPs that concurrently accessing more than auto_blacklist_llhls_max_connections unique LLHLS streams.

auto_blacklist_llhls_max_connections
integer

Maximum number of unique LLHLS streams that can be concurrently accessed before a given client IP is automatically blacklisted.

auto_blacklist_rtmp
boolean

Enable the automatic blacklisting of client IPs concurrently accessing more than auto_blacklist_rtmp_max_connections unique RTMP/S streams.

auto_blacklist_rtmp_max_connections
integer

Maximum number of unique RTMP/S streams that can be concurrently accessed before a given client IP is automatically blacklisted.

auto_blacklist_rtsp
boolean

Enable the automatic blacklisting of client IPs concurrently accessing more than auto_blacklist_rtsp_max_connections unique RTSP/S streams.

auto_blacklist_rtsp_max_connections
integer

Maximum number of unique RTSP/S streams that can be concurrently accessed before a given client IP is automatically blacklisted.

auto_blacklist_srt
boolean

Enable the automatic blacklisting of client IPs concurrently accessing more than auto_blacklist_srt_max_connections unique SRT streams.

auto_blacklist_srt_max_connections
integer

Maximum number of unique SRT streams that can be concurrently accessed before a given client IP is automatically blacklisted.

auto_blacklist_webrtc
boolean

Enable automatic blacklisting of client IPs concurrently accessing more than auto_blacklist_webrtc_max_connections unique WebRTC streams.

auto_blacklist_webrtc_max_connections
integer

Maximum number of unique WebRTC streams that can be concurrently accessed before a given client IP is automatically blacklisted.

auto_rotate_shared_secrets
boolean

Enable rotation of shared secrets for those streams that have auto rotate enabled. The shared secret will be rotated every auto_rotate_shared_secrets_period.

auto_rotate_shared_secrets_period_mins
integer

Time duration for automatically rotating shared secrets in minutes. Must be greater than or equal to 30.

Array of objects (data.IpListItem)

IPs/CIDRs carved out of blacklisted CIDRs and ASNs; never out of single-IP rows or auto_blacklist entries. Fleet-managed.

cdn_integration
boolean

Enable CDN integration for HLS/LLHLS overflow delivery.

enforce_allowed_origins
boolean

Reject HLS and WebRTC video requests from origins not included in the allowed_origins list.

firewall_integration
boolean

Enable streaming engine host (server) firewall rules management.

Array of objects (data.IpListItem)

HLS IP whitelist.

hls_mediaPlaylistName
string

Name of the HLS media playlist (optional). Default value is "xflow.m3u8".

hls_open_access
boolean

Enable HLS open access (unsecured).

hls_segmentCount
integer

Number of segments to include in HLS playlist. Minimum allowed value is 3.

hls_segmentDuration
integer

Duration of each segment in HLS playlist (in seconds). Minimum allowed value is 1.

Array of objects (data.IpListItem)

Operator blacklist: IPs, CIDRs and ASNs ("AS16509") blocked for video access (ASN_BLACKLIST.md). Fleet-managed.

last_shared_secrets_rotation
string

Timestamp of the last rotation of shared secrets.

last_updated
string

Date and time the cluster configuration was last updated.

lb_disabled_persistence_threshold_mins
integer

Load balancer disabled persistence threshold in minutes. Minimum allowed value is 1.

lb_evaluation_period_mins
integer

Load balancer evaluation period in minutes. Minimum allowed value is 1.

lb_failover_persistence_threshold_mins
integer

Load balancer failover persistence threshold in minutes. Minimum allowed value is 1.

lb_max_per_period_reassignment_count
integer

Load balancer maximum per evaluation period reassignment count. Maximum per evaluation period stream reassignment count. After reassigning the maximum period reassignment count, XFlow will wait the load balancer evaluation period, then reassess the availability of servers for additional reassignments. Minimum allowed value is 0 (no reassignments).

lb_overloaded_persistence_threshold_mins
integer

Load balancer overloaded persistence threshold in minutes. Minimum allowed value is 1.

lb_server_available_threshold_pct
integer

Load balancer server available threshold percentage. The resource utilization threshold below which the server is considered to be available for stream reassignment. Allowed range is 0 to 90. The available threshold percentage must be at least 5% less than the overloaded threshold percentage.

lb_server_overloaded_threshold_pct
integer

Load balancer server overloaded threshold percentage. The resource utilization threshold above which the server is considered to be overloaded. Allowed range is 30 to 100. The overloaded threshold percentage must be at least 5 percent greater than the available threshold percentage.

Array of objects (data.IpListItem)

LL-HLS IP whitelist.

llhls_open_access
boolean

Enable LL-HLS open access (unsecured).

llhls_segmentCount
integer

Number of segments to include in LLHLS playlist. Minimum allowed value is 7.

llhls_segmentDuration
integer

Duration of each segment in LLHLS playlist (in seconds). Minimum allowed value is 1.

Array of objects (data.IpListItem)

Recording playback IP whitelist.

playback_open_access
boolean

Enable recording playback open access (unsecured).

private_dns_enabled
boolean

Enable application of the private DNS host overrides (private_hosts) on streaming engines, for source-stream name resolution.

Array of objects (data.PrivateHostItem)

Private hostname→IP overrides applied to source-stream name resolution (single IP each, no CIDR). Applied only when private_dns_enabled is true.

ptz_preset_filter
string
Enum: "none" "contains" "starts_with" "ends_with"

Manager Settings — PTZ preset filter. Applied inside the camera drivers as presets are read from each camera, so a preset that does not pass is never cached, stored or reported anywhere (players, Cameras Status, Camera Configuration preset tours) for any role. Same semantics as the Snaps / XCube stream filters (see data.MatchesConfigFilter). Fleet-managed.

ptz_preset_filter_value
string

Value to be used with the PTZ preset filter. Required when the filter is not 'none'. A leading '!' inverts the match (matching presets are hidden, all others shown). Case-sensitive.

record_delete_after
string

Default retention. Segments are deleted after this timespan. 0s disables age-based deletion (watermark pruning still applies). e.g. 24h.

record_part_duration
string

Recording (cluster-wide policy). The storage root and per-server enable live in ServerConfigTarget; these uniform policy fields apply to every recording server. Durations are strings with units up to hours (e.g. 1s, 1h, 24h).

record_segment_duration
string

Minimum duration of each recording segment file. e.g. 10m.

record_sync
boolean

When true, each recording part is fsync'd to disk as written (bounds the power-loss window to ~one part; costs throughput).

Array of objects (data.IpListItem)

RTMP IP whitelist.

rtmp_open_access
boolean

Enable RTMP open access (unsecured).

Array of objects (data.IpListItem)

RTSP IP whitelist.

rtsp_open_access
boolean

Enable RTSP open access (unsecured).

secure_token_hls
boolean

Enforce auth token for HLS output.

secure_token_llhls
boolean

Enforce auth token for LL-HLS output.

secure_token_playback
boolean

Enforce auth token for recording playback.

secure_token_rtmp
boolean

Enforce auth token for RTMP/S output.

secure_token_rtsp
boolean

Enforce auth token for RTSP/S output.

secure_token_wrtc
boolean

Enforce auth token for WebRTC output.

Array of objects (data.TokenListItem)

Shared auth token list.

snaps_host
string

IP address or hostname of server hosting Snaps service.

snaps_integration
boolean

Enable integration with Snaps service (for snapshot collection, processing, and publishing).

snaps_port
integer

Snaps service API port number.

snaps_public_host_folder_url
string

Public URL of snapshots host folder (optional). If provided, it will be used by the XFlow web UI (Cameras view).

snaps_secret
string

Snaps service API shared secret.

snaps_stream_filter
string
Enum: "none" "contains" "starts_with" "ends_with"

Filter to apply to stream identifiers in providing / syncing output stream access information.

snaps_stream_filter_value
string

Value to be used with the stream identifier filter in providing / syncing output stream access information.

snaps_use_https
boolean

Use HTTPS to access Snaps service API.

Array of objects (data.IpListItem)

SRT IP whitelist.

srt_open_access
boolean

Enable SRT open access (unsecured).

Array of objects (data.VideoWallIntegrationConfig)

List of video wall controller API integration configurations (e.g., XCube, Datapath).

webrtc_player_dns
string

DNS (URL) to be used by the built-in WebRTC player. Default value is "https://dns.google/resolve".

Array of objects (data.IpListItem)

WebRTC IP whitelist.

wrtc_open_access
boolean

Enable WebRTC open access (unsecured).

Array of objects (data.XCubeIntegrationConfig)

List of XCube Display Manager integration configurations.

Responses

Request samples

Content type
application/json
{
  • "admin_access_restriction_enabled": true,
  • "admin_ip_whitelist": [
    ],
  • "allowed_origins": [
    ],
  • "auto_blacklist": [
    ],
  • "auto_blacklist_duration_hours": 0,
  • "auto_blacklist_hls": true,
  • "auto_blacklist_hls_max_connections": 0,
  • "auto_blacklist_ip_exemptions": [
    ],
  • "auto_blacklist_llhls": true,
  • "auto_blacklist_llhls_max_connections": 0,
  • "auto_blacklist_rtmp": true,
  • "auto_blacklist_rtmp_max_connections": 0,
  • "auto_blacklist_rtsp": true,
  • "auto_blacklist_rtsp_max_connections": 0,
  • "auto_blacklist_srt": true,
  • "auto_blacklist_srt_max_connections": 0,
  • "auto_blacklist_webrtc": true,
  • "auto_blacklist_webrtc_max_connections": 0,
  • "auto_rotate_shared_secrets": true,
  • "auto_rotate_shared_secrets_period_mins": 0,
  • "blacklist_exemptions": [
    ],
  • "cdn_integration": true,
  • "enforce_allowed_origins": true,
  • "firewall_integration": true,
  • "hls_ip_whitelist": [
    ],
  • "hls_mediaPlaylistName": "string",
  • "hls_open_access": true,
  • "hls_segmentCount": 0,
  • "hls_segmentDuration": 0,
  • "ip_blacklist": [
    ],
  • "last_shared_secrets_rotation": "string",
  • "last_updated": "string",
  • "lb_disabled_persistence_threshold_mins": 0,
  • "lb_evaluation_period_mins": 0,
  • "lb_failover_persistence_threshold_mins": 0,
  • "lb_max_per_period_reassignment_count": 0,
  • "lb_overloaded_persistence_threshold_mins": 0,
  • "lb_server_available_threshold_pct": 0,
  • "lb_server_overloaded_threshold_pct": 0,
  • "llhls_ip_whitelist": [
    ],
  • "llhls_open_access": true,
  • "llhls_segmentCount": 0,
  • "llhls_segmentDuration": 0,
  • "playback_ip_whitelist": [
    ],
  • "playback_open_access": true,
  • "private_dns_enabled": true,
  • "private_hosts": [
    ],
  • "ptz_preset_filter": "none",
  • "ptz_preset_filter_value": "string",
  • "record_delete_after": "string",
  • "record_part_duration": "string",
  • "record_segment_duration": "string",
  • "record_sync": true,
  • "rtmp_ip_whitelist": [
    ],
  • "rtmp_open_access": true,
  • "rtsp_ip_whitelist": [
    ],
  • "rtsp_open_access": true,
  • "secure_token_hls": true,
  • "secure_token_llhls": true,
  • "secure_token_playback": true,
  • "secure_token_rtmp": true,
  • "secure_token_rtsp": true,
  • "secure_token_wrtc": true,
  • "shared_auth_tokens": [
    ],
  • "snaps_host": "string",
  • "snaps_integration": true,
  • "snaps_port": 0,
  • "snaps_public_host_folder_url": "string",
  • "snaps_secret": "string",
  • "snaps_stream_filter": "none",
  • "snaps_stream_filter_value": "string",
  • "snaps_use_https": true,
  • "srt_ip_whitelist": [
    ],
  • "srt_open_access": true,
  • "video_wall_integration_list": [
    ],
  • "webrtc_player_dns": "string",
  • "wrtc_ip_whitelist": [
    ],
  • "wrtc_open_access": true,
  • "xcube_integration_list": [
    ]
}

Response samples

Content type
application/json
{
  • "clusterConfig": {
    },
  • "message": "string"
}

Set managed cluster configuration fields

Partially updates ONLY the centrally-managed cluster-config fields (for XConductor). Site-local integration, auto_blacklist, and runtime fields are left untouched; ip_blacklist and blacklist_exemptions are written only when the request carries them. Uses a field-scoped update to avoid racing the auto-blacklister.

Authorizations:
OAuth2Password
Request Body schema: application/json
required

Managed cluster configuration fields

admin_access_restriction_enabled
boolean
Array of objects (data.IpListItem)
Array of objects (data.OriginListItem)
auto_blacklist_duration_hours
integer
auto_blacklist_hls
boolean
auto_blacklist_hls_max_connections
integer
Array of objects (data.IpListItem)
auto_blacklist_llhls
boolean
auto_blacklist_llhls_max_connections
integer
auto_blacklist_rtmp
boolean
auto_blacklist_rtmp_max_connections
integer
auto_blacklist_rtsp
boolean
auto_blacklist_rtsp_max_connections
integer
auto_blacklist_srt
boolean
auto_blacklist_srt_max_connections
integer
auto_blacklist_webrtc
boolean
auto_blacklist_webrtc_max_connections
integer
auto_rotate_shared_secrets
boolean
auto_rotate_shared_secrets_period_mins
integer
Array of objects (data.IpListItem)
cdn_integration
boolean
enforce_allowed_origins
boolean
firewall_integration
boolean
Array of objects (data.IpListItem)
hls_mediaPlaylistName
string
hls_open_access
boolean
hls_segmentCount
integer
hls_segmentDuration
integer
Array of objects (data.IpListItem)
lb_disabled_persistence_threshold_mins
integer
lb_evaluation_period_mins
integer
lb_failover_persistence_threshold_mins
integer
lb_max_per_period_reassignment_count
integer
lb_overloaded_persistence_threshold_mins
integer
lb_server_available_threshold_pct
integer
lb_server_overloaded_threshold_pct
integer
Array of objects (data.IpListItem)
llhls_open_access
boolean
llhls_segmentCount
integer
llhls_segmentDuration
integer
Array of objects (data.IpListItem)
playback_open_access
boolean
private_dns_enabled
boolean
Array of objects (data.PrivateHostItem)
ptz_preset_filter
string (data.StreamConfigFilter)
Enum: "none" "contains" "starts_with" "ends_with"
ptz_preset_filter_value
string
record_delete_after
string
record_part_duration
string
record_segment_duration
string
record_sync
boolean
Array of objects (data.IpListItem)
rtmp_open_access
boolean
Array of objects (data.IpListItem)
rtsp_open_access
boolean
secure_token_hls
boolean
secure_token_llhls
boolean
secure_token_playback
boolean
secure_token_rtmp
boolean
secure_token_rtsp
boolean
secure_token_wrtc
boolean
Array of objects (data.TokenListItem)
Array of objects (data.IpListItem)
srt_open_access
boolean
webrtc_player_dns
string
Array of objects (data.IpListItem)
wrtc_open_access
boolean

Responses

Request samples

Content type
application/json
{
  • "admin_access_restriction_enabled": true,
  • "admin_ip_whitelist": [
    ],
  • "allowed_origins": [
    ],
  • "auto_blacklist_duration_hours": 0,
  • "auto_blacklist_hls": true,
  • "auto_blacklist_hls_max_connections": 0,
  • "auto_blacklist_ip_exemptions": [
    ],
  • "auto_blacklist_llhls": true,
  • "auto_blacklist_llhls_max_connections": 0,
  • "auto_blacklist_rtmp": true,
  • "auto_blacklist_rtmp_max_connections": 0,
  • "auto_blacklist_rtsp": true,
  • "auto_blacklist_rtsp_max_connections": 0,
  • "auto_blacklist_srt": true,
  • "auto_blacklist_srt_max_connections": 0,
  • "auto_blacklist_webrtc": true,
  • "auto_blacklist_webrtc_max_connections": 0,
  • "auto_rotate_shared_secrets": true,
  • "auto_rotate_shared_secrets_period_mins": 0,
  • "blacklist_exemptions": [
    ],
  • "cdn_integration": true,
  • "enforce_allowed_origins": true,
  • "firewall_integration": true,
  • "hls_ip_whitelist": [
    ],
  • "hls_mediaPlaylistName": "string",
  • "hls_open_access": true,
  • "hls_segmentCount": 0,
  • "hls_segmentDuration": 0,
  • "ip_blacklist": [
    ],
  • "lb_disabled_persistence_threshold_mins": 0,
  • "lb_evaluation_period_mins": 0,
  • "lb_failover_persistence_threshold_mins": 0,
  • "lb_max_per_period_reassignment_count": 0,
  • "lb_overloaded_persistence_threshold_mins": 0,
  • "lb_server_available_threshold_pct": 0,
  • "lb_server_overloaded_threshold_pct": 0,
  • "llhls_ip_whitelist": [
    ],
  • "llhls_open_access": true,
  • "llhls_segmentCount": 0,
  • "llhls_segmentDuration": 0,
  • "playback_ip_whitelist": [
    ],
  • "playback_open_access": true,
  • "private_dns_enabled": true,
  • "private_hosts": [
    ],
  • "ptz_preset_filter": "none",
  • "ptz_preset_filter_value": "string",
  • "record_delete_after": "string",
  • "record_part_duration": "string",
  • "record_segment_duration": "string",
  • "record_sync": true,
  • "rtmp_ip_whitelist": [
    ],
  • "rtmp_open_access": true,
  • "rtsp_ip_whitelist": [
    ],
  • "rtsp_open_access": true,
  • "secure_token_hls": true,
  • "secure_token_llhls": true,
  • "secure_token_playback": true,
  • "secure_token_rtmp": true,
  • "secure_token_rtsp": true,
  • "secure_token_wrtc": true,
  • "shared_auth_tokens": [
    ],
  • "srt_ip_whitelist": [
    ],
  • "srt_open_access": true,
  • "webrtc_player_dns": "string",
  • "wrtc_ip_whitelist": [
    ],
  • "wrtc_open_access": true
}

Response samples

Content type
application/json
{
  • "clusterConfig": {
    },
  • "message": "string"
}

Server Configuration

Get server configuration list

Gets the list of server configurations

Authorizations:
OAuth2Password

Responses

Response samples

Content type
application/json
{
  • "message": "string",
  • "serverCount": 0,
  • "serversConfig": [
    ]
}

Add server configuration

Adds a new server configuration

Authorizations:
OAuth2Password
Request Body schema: application/json
required

Server configuration

cdn_hls_host
string

Optional CDN edge hostname for HLS overflow. Empty = CDN not used for HLS.

cdn_llhls_host
string

Optional CDN edge hostname for LLHLS overflow. Empty = CDN not used for LLHLS.

description
string

Optional description of server.

disabled
boolean

Server disabled. When disabled, the server does not ingest any streams. Previously assigned streams may be migrated to other servers, depending on the load balancing configuration, and the availability of other servers.

hls_http_port
integer

HLS HTTP port (for HLS stream access).

hls_secure
boolean

HTTPS enabled for HLS.

last_updated
string

Date and time the server configuration was last updated.

lb_participant
boolean

Participates in load balancing and failover operations. The server may be used to host streams 'owned' by other servers, in the event that those servers become disabled, unavailable, or overloaded.

llhls_http_port
integer

Low-Latency HLS HTTP port (for LLHLS stream access).

llhls_secure
boolean

HTTPS enabled for Low-Latency HLS.

multicast_ip_range
string

RTSP multicast IP range (CIDR).

multicast_rtcp_port
integer

Multicast RTCP port (for RTSP Multicast UDP stream access).

multicast_rtp_port
integer

Multicast RTP port (for RTSP Multicast UDP stream access).

name
string

Unique, alphanumeric server name or identifier. No spaces or special characters allowed (except for '-' and '_').

playback_enabled
boolean

Recording playback exposed on this server. When enabled, playback retrieval URLs are surfaced for this server's streams.

playback_port
integer

Playback port (for recording retrieval / playback).

playback_secure
boolean

HTTPS enabled for recording playback.

record
boolean

Recording provisioning (per-server; storage varies by host). The storage root and enable are per-server; the segment/part durations, retention, and sync policy are cluster-wide (see ClusterConfig). A stream is recorded only when this server has Record enabled AND the stream opts in.

record_disk_min_free_percent
integer

Reserved free-space headroom (%). When free space on the record volume drops below this, the oldest segments across all streams are pruned ahead of retention. 0 disables watermark pruning.

record_path
string

Absolute storage root for recordings on this server. Required when Record is enabled.

rtcp_port
integer

RTCP port (for RTSP UDP stream access).

rtmp_port
integer

RTMP port (for RTMP stream access).

rtmp_secure
boolean

RTMPS enabled (TLS encrypted RTMP).

rtmps_port
integer

RTMPS port (for RTMPS stream access).

rtp_port
integer

RTP port (for RTSP UDP stream access).

rtsp_multicast
boolean

RTSP multicast enabled.

rtsp_port
integer

RTSP port (for RTSP stream access).

rtsp_secure
boolean

RTSPS enabled (TLS encrypted RTSP).

rtsps_port
integer

RTSPS port (for RTSPS stream access).

se_api_host
string

IP address or hostname of server.

se_api_http_port
integer

Port for server (SE instance) API.

se_api_password
string

Password for server (SE instance) API.

se_api_secure
boolean

HTTPS enabled for server (SE instance) API.

se_api_user
string

Username for server (SE instance) API.

srt_port
integer

SRT port (for SRT stream access).

video_host
string

Video consumer facing IP address or hostname of server.

webrtc_http_port
integer

WebRTC HTTP port (for WebRTC stream requests / signalling).

webrtc_secure
boolean

HTTPS enabled for WebRTC.

webrtc_udp_port
integer

WebRTC UDP port (for WebRTC stream / video delivery).

Responses

Request samples

Content type
application/json
{
  • "cdn_hls_host": "string",
  • "cdn_llhls_host": "string",
  • "description": "string",
  • "disabled": true,
  • "hls_http_port": 0,
  • "hls_secure": true,
  • "last_updated": "string",
  • "lb_participant": true,
  • "llhls_http_port": 0,
  • "llhls_secure": true,
  • "multicast_ip_range": "string",
  • "multicast_rtcp_port": 0,
  • "multicast_rtp_port": 0,
  • "name": "string",
  • "playback_enabled": true,
  • "playback_port": 0,
  • "playback_secure": true,
  • "record": true,
  • "record_disk_min_free_percent": 0,
  • "record_path": "string",
  • "rtcp_port": 0,
  • "rtmp_port": 0,
  • "rtmp_secure": true,
  • "rtmps_port": 0,
  • "rtp_port": 0,
  • "rtsp_multicast": true,
  • "rtsp_port": 0,
  • "rtsp_secure": true,
  • "rtsps_port": 0,
  • "se_api_host": "string",
  • "se_api_http_port": 0,
  • "se_api_password": "string",
  • "se_api_secure": true,
  • "se_api_user": "string",
  • "srt_port": 0,
  • "video_host": "string",
  • "webrtc_http_port": 0,
  • "webrtc_secure": true,
  • "webrtc_udp_port": 0
}

Response samples

Content type
application/json
{
  • "message": "string",
  • "serverConfig": {
    }
}

Delete server configuration

Deletes the server configuration

Authorizations:
OAuth2Password
path Parameters
name
required
string

Server name

Responses

Response samples

Content type
application/json
"string"

Disable server configuration list

Disables the server configuration list

Authorizations:
OAuth2Password

Responses

Response samples

Content type
application/json
"string"

Disable server configuration

Disables the server configuration

Authorizations:
OAuth2Password
path Parameters
name
required
string

Server name

Responses

Response samples

Content type
application/json
"string"

Enable server configuration list

Enables the server configuration list

Authorizations:
OAuth2Password

Responses

Response samples

Content type
application/json
"string"

Enable server configuration

Enables the server configuration

Authorizations:
OAuth2Password
path Parameters
name
required
string

Server name

Responses

Response samples

Content type
application/json
"string"

Update server configuration

Updates the server configuration

Authorizations:
OAuth2Password
path Parameters
name
required
string

Server name

Request Body schema: application/json
required

Server configuration

cdn_hls_host
string

Optional CDN edge hostname for HLS overflow. Empty = CDN not used for HLS.

cdn_llhls_host
string

Optional CDN edge hostname for LLHLS overflow. Empty = CDN not used for LLHLS.

description
string

Optional description of server.

disabled
boolean

Server disabled. When disabled, the server does not ingest any streams. Previously assigned streams may be migrated to other servers, depending on the load balancing configuration, and the availability of other servers.

hls_http_port
integer

HLS HTTP port (for HLS stream access).

hls_secure
boolean

HTTPS enabled for HLS.

last_updated
string

Date and time the server configuration was last updated.

lb_participant
boolean

Participates in load balancing and failover operations. The server may be used to host streams 'owned' by other servers, in the event that those servers become disabled, unavailable, or overloaded.

llhls_http_port
integer

Low-Latency HLS HTTP port (for LLHLS stream access).

llhls_secure
boolean

HTTPS enabled for Low-Latency HLS.

multicast_ip_range
string

RTSP multicast IP range (CIDR).

multicast_rtcp_port
integer

Multicast RTCP port (for RTSP Multicast UDP stream access).

multicast_rtp_port
integer

Multicast RTP port (for RTSP Multicast UDP stream access).

name
string

Unique, alphanumeric server name or identifier. No spaces or special characters allowed (except for '-' and '_').

playback_enabled
boolean

Recording playback exposed on this server. When enabled, playback retrieval URLs are surfaced for this server's streams.

playback_port
integer

Playback port (for recording retrieval / playback).

playback_secure
boolean

HTTPS enabled for recording playback.

record
boolean

Recording provisioning (per-server; storage varies by host). The storage root and enable are per-server; the segment/part durations, retention, and sync policy are cluster-wide (see ClusterConfig). A stream is recorded only when this server has Record enabled AND the stream opts in.

record_disk_min_free_percent
integer

Reserved free-space headroom (%). When free space on the record volume drops below this, the oldest segments across all streams are pruned ahead of retention. 0 disables watermark pruning.

record_path
string

Absolute storage root for recordings on this server. Required when Record is enabled.

rtcp_port
integer

RTCP port (for RTSP UDP stream access).

rtmp_port
integer

RTMP port (for RTMP stream access).

rtmp_secure
boolean

RTMPS enabled (TLS encrypted RTMP).

rtmps_port
integer

RTMPS port (for RTMPS stream access).

rtp_port
integer

RTP port (for RTSP UDP stream access).

rtsp_multicast
boolean

RTSP multicast enabled.

rtsp_port
integer

RTSP port (for RTSP stream access).

rtsp_secure
boolean

RTSPS enabled (TLS encrypted RTSP).

rtsps_port
integer

RTSPS port (for RTSPS stream access).

se_api_host
string

IP address or hostname of server.

se_api_http_port
integer

Port for server (SE instance) API.

se_api_password
string

Password for server (SE instance) API.

se_api_secure
boolean

HTTPS enabled for server (SE instance) API.

se_api_user
string

Username for server (SE instance) API.

srt_port
integer

SRT port (for SRT stream access).

video_host
string

Video consumer facing IP address or hostname of server.

webrtc_http_port
integer

WebRTC HTTP port (for WebRTC stream requests / signalling).

webrtc_secure
boolean

HTTPS enabled for WebRTC.

webrtc_udp_port
integer

WebRTC UDP port (for WebRTC stream / video delivery).

Responses

Request samples

Content type
application/json
{
  • "cdn_hls_host": "string",
  • "cdn_llhls_host": "string",
  • "description": "string",
  • "disabled": true,
  • "hls_http_port": 0,
  • "hls_secure": true,
  • "last_updated": "string",
  • "lb_participant": true,
  • "llhls_http_port": 0,
  • "llhls_secure": true,
  • "multicast_ip_range": "string",
  • "multicast_rtcp_port": 0,
  • "multicast_rtp_port": 0,
  • "name": "string",
  • "playback_enabled": true,
  • "playback_port": 0,
  • "playback_secure": true,
  • "record": true,
  • "record_disk_min_free_percent": 0,
  • "record_path": "string",
  • "rtcp_port": 0,
  • "rtmp_port": 0,
  • "rtmp_secure": true,
  • "rtmps_port": 0,
  • "rtp_port": 0,
  • "rtsp_multicast": true,
  • "rtsp_port": 0,
  • "rtsp_secure": true,
  • "rtsps_port": 0,
  • "se_api_host": "string",
  • "se_api_http_port": 0,
  • "se_api_password": "string",
  • "se_api_secure": true,
  • "se_api_user": "string",
  • "srt_port": 0,
  • "video_host": "string",
  • "webrtc_http_port": 0,
  • "webrtc_secure": true,
  • "webrtc_udp_port": 0
}

Response samples

Content type
application/json
{
  • "message": "string",
  • "serverConfig": {
    }
}

Get server configuration

Gets the server configuration

Authorizations:
OAuth2Password
path Parameters
name
required
string

Server name

Responses

Response samples

Content type
application/json
{
  • "message": "string",
  • "serverConfig": {
    }
}

Reboot host machine for every server

Triggers a systemctl reboot on the host machine of all servers

Authorizations:
OAuth2Password

Responses

Response samples

Content type
application/json
"string"

Reboot host machine for a server

Triggers a systemctl reboot on the host machine of the target server

Authorizations:
OAuth2Password
path Parameters
name
required
string

Server name

Responses

Response samples

Content type
application/json
"string"

Restart XENGINE service on every server

Triggers a systemctl restart of the restreamer service on all servers

Authorizations:
OAuth2Password

Responses

Response samples

Content type
application/json
"string"

Restart XENGINE service on a server

Triggers a systemctl restart of the restreamer service on the target server

Authorizations:
OAuth2Password
path Parameters
name
required
string

Server name

Responses

Response samples

Content type
application/json
"string"

Server Status

Get server connections list

Gets the list of server connections

Authorizations:
OAuth2Password

Responses

Response samples

Content type
application/json
{
  • "message": "string",
  • "serverCount": 0,
  • "serversConnections": [
    ]
}

Get server connections

Gets the server connections

Authorizations:
OAuth2Password
path Parameters
name
required
string

Server name

Responses

Response samples

Content type
application/json
{
  • "message": "string",
  • "serverConnections": {
    }
}

Get server statistics list

Gets the list of server statistics

Authorizations:
OAuth2Password

Responses

Response samples

Content type
application/json
{
  • "message": "string",
  • "serverCount": 0,
  • "serversStats": [
    ]
}

Get server statistics archive list

Gets the server statistics archive list

Authorizations:
OAuth2Password
path Parameters
name
required
string

Server name

hours
required
number <float64>

Hours

Responses

Response samples

Content type
application/json
{
  • "message": "string",
  • "serverStatsHistory": [
    ]
}

Get server statistics

Gets the server statistics

Authorizations:
OAuth2Password
path Parameters
name
required
string

Server name

Responses

Response samples

Content type
application/json
{
  • "message": "string",
  • "serverStats": {
    }
}

Get server status list

Gets the list of server statuses

Authorizations:
OAuth2Password

Responses

Response samples

Content type
application/json
{
  • "message": "string",
  • "serverCount": 0,
  • "serversStatus": [
    ]
}

Get server status archived list

Gets the server status archived list

Authorizations:
OAuth2Password
path Parameters
name
required
string

Server name

hours
required
number <float64>

Hours

Responses

Response samples

Content type
application/json
{
  • "message": "string",
  • "serverStatusHistory": [
    ]
}

Get server status

Gets the server status

Authorizations:
OAuth2Password
path Parameters
name
required
string

Server name

Responses

Response samples

Content type
application/json
{
  • "message": "string",
  • "serverStatus": {
    }
}

Stream Configuration

Get stream configuration list

Gets the list of stream configurations

Authorizations:
OAuth2Password

Responses

Response samples

Content type
application/json
{
  • "message": "string",
  • "streamsConfig": [
    ],
  • "totalStreamCount": 0
}

Add stream configuration

Adds a new stream configuration

Authorizations:
OAuth2Password
Request Body schema: application/json
required

Stream configuration

always_multicast
boolean

Broadcast the stream to its outbound multicast group continuously while the source is up, whether or not clients are connected. Requires outbound_multicast_ip to be set, and takes effect only when always_on is enabled. When false, multicast emission is reader-driven.

always_on
boolean

Stream is always ingested, even when no clients are connected. When set to false, the stream is only ingested when clients are connected.

auto_rotate_secret
boolean

Automatically rotate the shared secret for the stream every auto rotated period.

composite
boolean

Composite (server-generated). When Composite is true this stream has no external source: it is produced on its assigned server by compositing two sibling streams — CompositePrimary as the full-frame base with CompositeInset overlaid in a corner. Mutually exclusive with source and conversion; recording is not supported in v1 (record the source streams instead). IMMUTABLE after creation (enforced by the update handler). v1 constraints enforced in the handler: both inputs must be non-composite streams pinned to this stream's home server, and the composite itself is pinned (load_balance forced false in IsValid).

composite_corner
string
Enum: "top_left" "top_right" "bottom_left" "bottom_right" "bottom_right"

Corner the inset anchors to: 'top_left', 'top_right', 'bottom_left', 'bottom_right'. Default 'bottom_right'.

composite_inset
string

Sibling stream name overlaid as the picture-in-picture inset.

composite_inset_size
string
Enum: "small" "medium" "large" "medium"

Inset size relative to the base frame: 'small', 'medium', 'large'. Default 'medium'.

composite_primary
string

Sibling stream name used as the full-frame base. Empty for a normal (sourced) stream.

composite_type
string
Enum: "pip" "pip"

Composite kind. v1: always 'pip' (picture-in-picture).

con_bitrate_kbps
integer

Target bitrate in kilobits per second for stream transcoding. Allowed range is 64 to 5000. Default is none specified (dynamic, based on source stream and other transcoding parameters).

con_fps
integer

Target frame rate in frames per second for stream transcoding. Allowed range is 5 to 60. If set to 0, source stream frame rate is used.

con_height
integer

Target height in pixels for stream transcoding. Allowed range is 64 to 2160. Default is none specified (source stream height is used). Both con_width and con_height must be set or both must be unset.

con_output_buffer_kb
integer

Used in HTTP based protocol conversion / transcoding. Size of conversion / transcoding output buffer in kilobytes. Allowed range is 0 to 60000. Default is 0 for RTSP source streams and 3000 for other source stream types.

con_preset
string
Enum: "veryfast" "ultrafast" "superfast" "veryfast" "faster" "fast" "medium" "slow" "slower" "veryslow"

H264 (libx264) preset for stream transcoding. Allowed values are "ultrafast", "superfast", "veryfast", "faster", "fast", "medium", "slow", "slower", "veryslow". Default is veryfast.

con_protocol
string
Enum: "rtsp" "rtsps" "rtmp" "rtmps" "application/x-mpegURL" "application/vnd.apple.mpegurl" "webrtc" "srt"

Target protocol for stream remuxing or transcoding. Allowed values are 'rtsp' and 'rtmp'. Used only when con_type is set to 'remux' or 'transcode'. Default value is 'rtmp'.

con_realtime
boolean

Optionally used in HTTP/HTTPS source stream conversion. Reading the source stream at its native frame rate is enabled, essentially simulating a 'live' stream. Can improve output stream stability when converting segment based source streams (e.g. HLS). Default is false.

con_remux_window_ms
integer

Used in HTTP based protocol conversion / transcoding. Maximum number of milliseconds to remux source stream frames. Can improve output stream stability when converting / transcoding segment based source streams (e.g. HLS). Allowed range is 1000 to 5000. Default is 1000.

con_type
string
Enum: "none" "remux" "transcode"

Allowed values are 'none', 'remux', and 'transcode'. When set to 'remux', the source stream is remuxed to rtsp or rtmp prior to restreaming. When set to 'transcode', the source stream is transcoded or re-encoded to H.264, based on the default or provided con_preset, con_bitrate_kbps, con_width, con_height and con_fps parameters. Note that the con_realtime and con_remux_window_ms parameters are only used for http/https source conversion.

con_width
integer

Target width in pixels for stream transcoding. Allowed range is 64 to 3840. Default is none specified (source stream width is used). Both con_width and con_height must be set or both must be unset.

description
string

Brief description of stream or stream source (camera name, camera location, etc.).

disabled
boolean

Stream disabled. The stream will not be ingested or restreamed.

edge_stream
boolean

This stream takes everything from another stream (origin_stream) rather than from a source of its own: its RTSP source for the viewers that need real media, and its HLS directly from the origin's server. It therefore has no source URL, transport, stream template or multicast settings — those are cleared. Requires origin_stream and the stream directory (DIRECTORY_ENABLED) on this manager. For an edge server that must not reach cameras directly: the origin is always ingesting, so its segments already exist and an HLS viewer waits for neither ingest nor segment accumulation, and starts no ingest on this stream's own server. WebRTC and RTSP viewers still do.

exclude_from_snaps
boolean

Exclude from Snaps Module integration. If true, the steam will be excluded from those provided to the Snaps Module for snapshot generation.

home_server
string

Unique, alphanumeric home server name or identifier. No spaces or special characters allowed (except for '-' and '_').

last_secret_rotation
string

Timestamp of the last rotation of the shared secret.

load_balance
boolean

Load balancing and failover is enabled for this stream. The stream will be moved to another server (if / when one is available), in the event of its home server being disabled, unavailable or overloaded.

origin_stream
string

Name of the stream this edge stream takes its source and HLS from. Must be another stream this manager knows, must not be this stream, and must not itself be an edge stream. Both URLs the engine needs are generated from this one name and point at this manager's stream directory, so nothing needs changing when the origin stream is reassigned between servers.

outbound_multicast_ip
string

Outbound multicast IP address for the stream (optional). If provided, must be a valid multicast IP address. If not provided, the assigned server will automatically select a multicast IP address from from the multicast CIDR configured for the server. RTSP multicast must be enabled on the assigned server.

Array of objects (data.PushTargetListItem)

List of push targets for the stream. Each target (e.g., rtsp://user:pass@remote.example.com:554/destpath) is a URL with a supported push protocol ("rtsp", "rtsps", "rtmp", "rtmps"). The stream will be continually pushed to each target in the list. Ignored when AlwaysOn is set to false.

record
boolean

Opt this stream into recording. Effective only when recording is provisioned on the assigned server (server Record enabled) — the storage root, format, and part/segment layout are engine-level and cannot vary per stream. Ignored when AlwaysOn is set to false: an on-demand stream is ingested only while a client is connected, so it has nothing continuous to record.

record_delete_after
string

Optional per-stream recording retention override (e.g. "48h"). Empty inherits the cluster-wide default retention. When set, must be a valid duration ("0s" or greater).

secure_token_on
boolean

Token based authentication is enabled for this stream. HTTP/HTTPS (HLS, LLHLS, and WebRTC) clients must use a valid auth token in order to access the stream.

server
string

Unique, alphanumeric currently assigned server name or identifier. No spaces or special characters allowed (except for '-' and '_'). Read-only field.

shared_secret
string

Shared (alphanumeric) secret used to generate auth tokens and srt passphrase for output streams. Must be 8 to 16 characters in length. Required when secure_token_on is enabled and auto_rotate_secret is disabled.

source
string

Source URL for the stream. Must be a valid URL with a supported protocol ("udp", "rtsp", "rtsps", "rtmp", "rtmps", "http", "https").

stream
string

Unique, lowercase, alphanumeric stream name or identifier. No spaces or special characters allowed, except for dashes, underscores, and periods. Used in output stream URLs.

stream_template
string

Optional. Explicitly binds this stream to a stream template for camera source-URL automation, taking precedence over the legacy "-