Core Hub APIs

The Core Hub provides a comprehensive suite of REST APIs for managing, monitoring, and automating your Gluesync deployment.

API Overview

Feature Description

Protocol

JSON REST APIs authenticated with JWT Bearer tokens

Default Port

:443 (if reverse proxy is enabled) or :1717 (if reverse proxy is disabled)

Security

Login with /authentication/login, then send Authorization: Bearer <token> on subsequent requests

Format

JSON request/response

Available Operations

  • Pipeline management

  • Entity configuration

  • Agent control

  • Task automation

  • User administration

  • System monitoring

API Documentation

Resource Access

Postman Collection

MOLO17 Gluesync Workspace

Swagger UI

http://COREHUBADDRESS/swagger (Replace COREHUBADDRESS with your server address. Authentication is required.)

Always use the appropriate protocol (HTTP/HTTPS) based on your security configuration.

Authentication

Gluesync uses JWT Bearer tokens for API access.

Log In and Get a Token

curl -X POST https://your-gluesync.com/authentication/login \
  -H "Content-Type: application/json" \
  -d '{"username": "admin", "password": "yourpassword"}'

The response includes the token and whether the account requires a password change:

{
  "token": "eyJhbGciOi...",
  "changeRequired": false
}

Use the Token on Subsequent Requests

curl -X GET https://your-gluesync.com/api/pipelines \
  -H "Authorization: Bearer <your-token>"

The browser and SPA use the gs-auth HttpOnly cookie automatically. Scripts and CLI tools must use the Bearer header.

Token Lifetime

Tokens expire when the session expires. The default session duration is 72 hours, and a SUPER ADMIN can change it in the server configuration.

Automation and Service Accounts

For automated scripts and scheduled jobs, create a dedicated local account.

Do not embed or reuse admin credentials in scripts.

OIDC users cannot authenticate programmatically through the API because there is no machine-to-machine OIDC login flow. If you need API automation, use a local account instead.

Using Swagger UI

Open http://COREHUBADDRESS/swagger, click Authorize, and paste your JWT token into the Authorize dialog when you need to try authenticated requests.

If you are testing from a fresh browser session, log in first so Swagger UI can load the protected API definitions.

Using the APIs

Object Identification

The Web Control Plane provides easy access to object IDs:

Control plane - pipeline ID

Feature Usage

ID Copying

Click on ID field for automatic clipboard copy

Quick Access

Use copied IDs directly in API calls

Best Practices

Security

  • Use HTTPS in production

  • Keep Bearer tokens out of client-side code and public repositories

  • Use dedicated local accounts for automation instead of shared admin credentials

  • Rotate credentials for service accounts periodically

  • Monitor API usage

Performance

  • Cache frequently used responses

  • Batch operations when possible

  • Use pagination for large datasets

  • Monitor response times