Core Hub APIs
The Core Hub provides a comprehensive suite of REST APIs for managing, monitoring, and automating your Gluesync deployment.
API Overview
| Feature | Description |
|---|---|
Protocol |
JSON REST APIs authenticated with JWT Bearer tokens |
Default Port |
:443 (if reverse proxy is enabled) or :1717 (if reverse proxy is disabled) |
Security |
Login with /authentication/login, then send Authorization: Bearer <token> on subsequent requests |
Format |
JSON request/response |
API Documentation
| Resource | Access |
|---|---|
Postman Collection |
|
Swagger UI |
http://COREHUBADDRESS/swagger (Replace COREHUBADDRESS with your server address. Authentication is required.) |
|
Always use the appropriate protocol (HTTP/HTTPS) based on your security configuration. |
Authentication
Gluesync uses JWT Bearer tokens for API access.
Log In and Get a Token
curl -X POST https://your-gluesync.com/authentication/login \
-H "Content-Type: application/json" \
-d '{"username": "admin", "password": "yourpassword"}'
The response includes the token and whether the account requires a password change:
{
"token": "eyJhbGciOi...",
"changeRequired": false
}
Use the Token on Subsequent Requests
curl -X GET https://your-gluesync.com/api/pipelines \
-H "Authorization: Bearer <your-token>"
|
The browser and SPA use the gs-auth HttpOnly cookie automatically. Scripts and CLI tools must use the Bearer header. |
Token Lifetime
Tokens expire when the session expires. The default session duration is 72 hours, and a SUPER ADMIN can change it in the server configuration.
Automation and Service Accounts
For automated scripts and scheduled jobs, create a dedicated local account.
|
Do not embed or reuse admin credentials in scripts. |
OIDC users cannot authenticate programmatically through the API because there is no machine-to-machine OIDC login flow. If you need API automation, use a local account instead.
