grafana/pkg/api
grafana-delivery-bot[bot] c100d2c684
[release-11.4.9] Forbid more redirect patterns (#110506)
2025-09-03 11:43:58 +02:00
..
apierrors
avatar
datasource
dtos Plugins: Add Subresource Integrity checks (#93024) 2024-10-04 14:55:09 +02:00
frontendlogging
pluginproxy apply security patch: release-11.4.4/366-202504020732.patch 2025-04-22 13:37:07 +00:00
response Chore: Move identity and errutil to apimachinery module (#89116) 2024-06-13 07:11:35 +03:00
routing
static [release-11.4.6]: Add static tests (#106132) 2025-05-28 16:03:31 +03:00
webassets WebAssets: improve checks and error messages on dtos (#92093) 2024-08-20 18:35:48 -03:00
README.md Chore: Fix Swagger/OpenAPI instructions (#86541) 2024-04-19 09:16:38 +03:00
accesscontrol.go UniStore: Evaluate Folder DTO attributes (#93968) 2024-10-07 12:08:16 +02:00
admin.go Chore: Move identity and errutil to apimachinery module (#89116) 2024-06-13 07:11:35 +03:00
admin_encryption.go
admin_provisioning.go
admin_provisioning_test.go
admin_test.go
admin_users.go [release-11.4.4] Auth: Fix SAML user IsExternallySynced not being set correctly (#103098) 2025-03-31 15:29:14 +02:00
admin_users_test.go [release-11.4.4] Auth: Fix SAML user IsExternallySynced not being set correctly (#103098) 2025-03-31 15:29:14 +02:00
alerting.go
annotations.go Folders: Set folder creation permission as part of legacy create (#94040) 2024-10-01 14:03:02 +02:00
annotations_test.go Folders: Set folder creation permission as part of legacy create (#94040) 2024-10-01 14:03:02 +02:00
api.go wire up unified search from the ui; add basic search support (#94358) 2024-10-08 13:09:56 -04:00
api_test.go
apikey.go UniStore: Evaluate Folder DTO attributes (#93968) 2024-10-07 12:08:16 +02:00
basic_auth.go
basic_auth_test.go
common_test.go Auth: Use sessionStorage instead of cookie for automatic redirection (#92759) 2024-09-24 18:38:09 +02:00
dashboard.go Instrument tracing across dashboards (#91937) 2024-08-29 22:26:15 -08:00
dashboard_permission.go Instrument tracing across dashboards (#91937) 2024-08-29 22:26:15 -08:00
dashboard_permission_test.go
dashboard_snapshot.go K8s: Improve identity mapping setup (#89450) 2024-06-20 17:53:07 +03:00
dashboard_snapshot_test.go Zanzana: Evaluate permissions alongside with RBAC engine (#90064) 2024-07-05 11:31:23 +02:00
dashboard_test.go Folders: Set folder creation permission as part of legacy create (#94040) 2024-10-01 14:03:02 +02:00
dataproxy.go
datasources.go [release-11.4.4] Go: Bump to 1.24.2 (#103527) 2025-04-08 17:24:40 +02:00
datasources_test.go Zanzana: Evaluate permissions alongside with RBAC engine (#90064) 2024-07-05 11:31:23 +02:00
ds_query.go Plugins: Remove datasourceQueryMultiStatus feature toggle (#90191) 2024-07-10 11:15:10 +02:00
ds_query_test.go Instrument tracing across accesscontrol (#91864) 2024-08-16 14:08:19 -08:00
fakes.go
folder.go Unified Storage /Folders: Allow Unified Storage subfolders creation (#94327) 2024-10-07 16:48:56 +02:00
folder_bench_test.go Folders: Set folder creation permission as part of legacy create (#94040) 2024-10-01 14:03:02 +02:00
folder_permission.go Chore: Move identity and errutil to apimachinery module (#89116) 2024-06-13 07:11:35 +03:00
folder_permission_test.go
folder_test.go UniStore: Evaluate Folder DTO attributes (#93968) 2024-10-07 12:08:16 +02:00
frontend_logging.go Chore: Bump Go to 1.23.0 (#92105) 2024-08-21 11:40:42 -04:00
frontend_logging_test.go
frontend_metrics.go
frontendsettings.go Plugins: Add Subresource Integrity checks (#93024) 2024-10-04 14:55:09 +02:00
frontendsettings_test.go Plugins: Add Subresource Integrity checks (#93024) 2024-10-04 14:55:09 +02:00
grafana_com_proxy.go
health.go
health_test.go
http_server.go wire up unified search from the ui; add basic search support (#94358) 2024-10-08 13:09:56 -04:00
http_server_test.go Grafana: Adds support for PKCS1 encrypted certs (#93451) 2024-09-19 15:03:06 -03:00
index.go Identity: Remove typed id (#91801) 2024-08-13 10:18:28 +02:00
login.go [release-11.4.9] Forbid more redirect patterns (#110506) 2025-09-03 11:43:58 +02:00
login_oauth.go Auth: Fix redirection when auto_login is enabled (#94311) 2024-10-07 14:59:00 +02:00
login_oauth_test.go Security: Fixes for CVE-2025-6197 and CVE-2025-6023 (#108279) 2025-07-17 15:06:55 -06:00
login_test.go [release-11.4.4] Auth: Fix SAML user IsExternallySynced not being set correctly (#103098) 2025-03-31 15:29:14 +02:00
org.go Identity: Remove typed id (#91801) 2024-08-13 10:18:28 +02:00
org_invite.go [v11.3.x] User: Check SignedInUser OrgID in RevokeInvite (#95490) 2024-10-28 14:42:19 +02:00
org_invite_test.go
org_test.go Identity: Remove typed id (#91801) 2024-08-13 10:18:28 +02:00
org_users.go [release-11.4.4] Auth: Fix SAML user IsExternallySynced not being set correctly (#103098) 2025-03-31 15:29:14 +02:00
org_users_test.go [release-11.4.4] Auth: Fix SAML user IsExternallySynced not being set correctly (#103098) 2025-03-31 15:29:14 +02:00
password.go [release-11.4.4] Auth: Fix SAML user IsExternallySynced not being set correctly (#103098) 2025-03-31 15:29:14 +02:00
playlist.go Storage: Test mode 5 (#93714) 2024-09-25 08:29:17 -04:00
plugin_checks.go Plugins: Avoid returning 404 for `AutoEnabled` apps (#93436) 2024-09-19 14:00:34 +01:00
plugin_checks_test.go Plugins: Avoid returning 404 for `AutoEnabled` apps (#93436) 2024-09-19 14:00:34 +01:00
plugin_dashboards.go
plugin_dashboards_test.go
plugin_metrics.go
plugin_metrics_test.go
plugin_proxy.go
plugin_proxy_test.go Plugins: Preserve trailing slash in plugin proxy (#86859) 2024-06-05 13:36:14 +02:00
plugin_resource.go
plugin_resource_test.go Plugins: Use handler middleware from the SDK (#93445) 2024-09-30 16:33:15 +02:00
plugins.go UniStore: Evaluate Folder DTO attributes (#93968) 2024-10-07 12:08:16 +02:00
plugins_test.go Plugins: Add Subresource Integrity checks (#93024) 2024-10-04 14:55:09 +02:00
preferences.go [release-11.4.7] IAM: Return 401 if identity type is not valid in GetUserPreferences (#107826) 2025-07-09 08:05:42 +01:00
preferences_test.go
quota.go chore: add tracing to quote API and service methods with contexts (#92211) 2024-08-21 13:24:45 -04:00
quota_test.go Add auth spans and remove deduplication code for scopes (#89804) 2024-07-02 22:08:57 -08:00
render.go Identity: remove GetTypedID (#91745) 2024-08-09 18:20:24 +03:00
search.go chore(tracing): add tracing for frontend and db session (#91509) 2024-08-05 17:17:39 -08:00
short_url.go
short_url_test.go
signup.go Identity: remove GetTypedID (#91745) 2024-08-09 18:20:24 +03:00
swagger.go Swagger: Add a custom swagger/api page (#91785) 2024-08-14 09:03:00 +03:00
swagger_responses.go API keys: Return 410 Gone status from POST /auth/keys endpoint (#92965) 2024-09-05 13:10:24 +03:00
swagger_tags.json
user.go [release-11.4.4] Auth: Fix SAML user IsExternallySynced not being set correctly (#103098) 2025-03-31 15:29:14 +02:00
user_test.go [release-11.4.4] Auth: Fix SAML user IsExternallySynced not being set correctly (#103098) 2025-03-31 15:29:14 +02:00
user_token.go [release-11.4.4] [IAM] Prepend AppSubURL to redirectURI before validating it (#104084) 2025-04-16 10:57:13 +02:00
user_token_test.go [release-11.4.9] Forbid more redirect patterns (#110506) 2025-09-03 11:43:58 +02:00
utils.go [release-11.4.4] Auth: Fix SAML user IsExternallySynced not being set correctly (#103098) 2025-03-31 15:29:14 +02:00

README.md

OpenAPI specifications

Since version 8.4, HTTP API details are specified using OpenAPI v2. Starting from version 9.1, there is also an OpenAPI v3 specification (generated by the v2 one using this script).

OpenAPI annotations

The OpenAPI v2 specification is generated automatically from the annotated Go code using go-swagger which scans the source code for annotation rules. Refer to this getting started guide for getting familiar with the toolkit.

Developers modifying the HTTP API endpoints need to make sure to add the necessary annotations so that their changes are reflected into the generated specifications.

Example of endpoint annotation

The following route defines a PATCH endpoint under the /serviceaccounts/{serviceAccountId} path with tag service_accounts (used for grouping together several routes) and operation ID updateServiceAccount (used for uniquely identifying routes and associate parameters and response with them).


// swagger:route PATCH /serviceaccounts/{serviceAccountId} service_accounts updateServiceAccount
//
// # Update service account
//
// Required permissions (See note in the [introduction](https://grafana.com/docs/grafana/latest/developers/http_api/serviceaccount/#service-account-api) for an explanation):
// action: `serviceaccounts:write` scope: `serviceaccounts:id:1` (single service account)
//
// Responses:
// 200: updateServiceAccountResponse
// 400: badRequestError
// 401: unauthorisedError
// 403: forbiddenError
// 404: notFoundError
// 500: internalServerError

The go-swagger can discover such annotations by scanning any code imported by pkg/server but by convention we place the endpoint annotations above the endpoint definition.

Example of endpoint parameters

The following struct defines the route parameters for the updateServiceAccount endpoint. The route expects:

  • a path parameter denoting the service account identifier and
  • a body parameter with the new values for the specific service account

// swagger:parameters updateServiceAccount
type UpdateServiceAccountParams struct {
	// in:path
	ServiceAccountId int64 `json:"serviceAccountId"`
	// in:body
	Body serviceaccounts.UpdateServiceAccountForm
}

Example of endpoint response

The following struct defines the response for the updateServiceAccount endpoint in case of a successful 200 response.


// swagger:response updateServiceAccountResponse
type UpdateServiceAccountResponse struct {
	// in:body
	Body struct {
		Message        string                                    `json:"message"`
		ID             int64                                     `json:"id"`
		Name           string                                    `json:"name"`
		ServiceAccount *serviceaccounts.ServiceAccountProfileDTO `json:"serviceaccount"`
	}
}

OpenAPI generation

Developers can re-create the OpenAPI v2 and v3 specifications using the following command:

make swagger-clean && make openapi3-gen

They can observe its output into the public/api-merged.json and public/openapi3.json files.

Finally, they can browser and try out both the OpenAPI v2 and v3 via the Swagger UI editor (served by the grafana server) by navigating to /swagger.

If there are any issues generating the specifications (e.g., diff containing unrelated changes to your PR or unusually large diff), please run the following two commands to ensure your Swagger version is up to date, then re-run the make commands.

  • go install github.com/bwplotka/bingo@latest
  • bingo get github.com/go-swagger/go-swagger/cmd/swagger@v0.30.2