Settings
The daemon settings file. Secret and identity keys are never read or written here.
On this page
Read the settings (secrets removed)
/settingsResponses
| Status | Description | Body | ||||||
|---|---|---|---|---|---|---|---|---|
| 200 | Settings | SettingsResponse | ||||||
| ||||||||
Errors 401 · 403 · 503
| 401 | Missing or wrong bearer token (unauthorized) | |
| 403 | The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin | |
| 503 | The subsystem is not configured on this daemon |
Error bodies use the error format.
Example
curl "http://127.0.0.1:7385/settings" \
-H "Authorization: Bearer $ADF_DAEMON_TOKEN"Merge settings values
/settingsNever writable here (403, no code): ownerMnemonic, runtimePrivateKey, runtimeEncPrivateKey, mcpOauthCredentials, trustedDaemonEncKeys, ownerDid, ownerEncPublicKey, runtimeDid, runtimeEncPublicKey, runtimeDelegation, legacyOwnerDids, legacyRuntimeDids, daemonRuntimeDid, daemonRuntimeDelegation, ownerDidSeedDerived. The owner identity changes only through /identity. A providers[].apiKey of __redacted__ keeps the stored key.
Request bodyapplication/json · SettingsPatchBody · required
Keys to merge. Secret and identity keys are refused (403); providers[].apiKey __redacted__ keeps the stored key.
No fields.
Responses
| Status | Description | Body | ||||||
|---|---|---|---|---|---|---|---|---|
| 200 | Settings after the merge | SettingsResponse | ||||||
| ||||||||
Errors 400 · 401 · 403 · 405 · 503
| 400 | Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY | |
| 401 | Missing or wrong bearer token (unauthorized) | |
| 403 | A secret or identity settings key cannot be written over HTTP (setting_not_writable), or the request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin) | |
| 405 | Not available on this daemon (the subsystem is read-only or lacks this operation) | |
| 503 | The subsystem is not configured on this daemon |
Error bodies use the error format.
Example
curl -X PATCH "http://127.0.0.1:7385/settings" \
-H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
-H "Content-Type: application/json" \
-d '{"meshEnabled":false}'Read one setting
/settings/{key}Secret keys read as null; providers[].apiKey as __redacted__.
Path parameters
| Name | Type | Description |
|---|---|---|
keyrequired | string | Settings key |
Responses
| Status | Description | Body | ||||||
|---|---|---|---|---|---|---|---|---|
| 200 | Value | SettingValueResponse | ||||||
| ||||||||
Errors 401 · 403 · 503
| 401 | Missing or wrong bearer token (unauthorized) | |
| 403 | The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin | |
| 503 | The subsystem is not configured on this daemon |
Error bodies use the error format.
Example
curl "http://127.0.0.1:7385/settings/meshEnabled" \
-H "Authorization: Bearer $ADF_DAEMON_TOKEN"{
"key": "meshEnabled",
"value": true
}Write one setting
/settings/{key}Never writable here (403, no code): ownerMnemonic, runtimePrivateKey, runtimeEncPrivateKey, mcpOauthCredentials, trustedDaemonEncKeys, ownerDid, ownerEncPublicKey, runtimeDid, runtimeEncPublicKey, runtimeDelegation, legacyOwnerDids, legacyRuntimeDids, daemonRuntimeDid, daemonRuntimeDelegation, ownerDidSeedDerived. The owner identity changes only through /identity. A providers[].apiKey of __redacted__ keeps the stored key.
Path parameters
| Name | Type | Description |
|---|---|---|
keyrequired | string | Settings key |
Request bodyapplication/json · SettingPutBody · required
| Field | Type | Description |
|---|---|---|
valuerequired | any | Any JSON value |
Responses
| Status | Description | Body | ||||||
|---|---|---|---|---|---|---|---|---|
| 200 | Stored value | SettingValueResponse | ||||||
| ||||||||
Errors 400 · 401 · 403 · 405 · 503
| 400 | Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY | |
| 401 | Missing or wrong bearer token (unauthorized) | |
| 403 | A secret or identity settings key cannot be written over HTTP (setting_not_writable), or the request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin) | |
| 405 | Not available on this daemon (the subsystem is read-only or lacks this operation) | |
| 503 | The subsystem is not configured on this daemon |
Error bodies use the error format.
Example
curl -X PUT "http://127.0.0.1:7385/settings/meshEnabled" \
-H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
-H "Content-Type: application/json" \
-d '{"value":true}'{
"key": "meshEnabled",
"value": true
}