On this page

Read the settings (secrets removed)

GET/settings

Operation getSettingsAuthBearer token

Responses

StatusDescriptionBody
200SettingsSettingsResponse
filePathrequiredstring | null
settingsrequiredobject | null

Secret keys removed; providers[].apiKey reads __redacted__

Errors 401 · 403 · 503
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
503The subsystem is not configured on this daemon

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/settings" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

Merge settings values

PATCH/settings

Operation patchSettingsAuthBearer token

Never writable here (403, no code): ownerMnemonic, runtimePrivateKey, runtimeEncPrivateKey, mcpOauthCredentials, trustedDaemonEncKeys, ownerDid, ownerEncPublicKey, runtimeDid, runtimeEncPublicKey, runtimeDelegation, legacyOwnerDids, legacyRuntimeDids, daemonRuntimeDid, daemonRuntimeDelegation, ownerDidSeedDerived. The owner identity changes only through /identity. A providers[].apiKey of __redacted__ keeps the stored key.

Request bodyapplication/json · SettingsPatchBody · required

Keys to merge. Secret and identity keys are refused (403); providers[].apiKey __redacted__ keeps the stored key.

No fields.

Responses

StatusDescriptionBody
200Settings after the mergeSettingsResponse
filePathrequiredstring | null
settingsrequiredobject | null

Secret keys removed; providers[].apiKey reads __redacted__

Errors 400 · 401 · 403 · 405 · 503
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403A secret or identity settings key cannot be written over HTTP (setting_not_writable), or the request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)
405Not available on this daemon (the subsystem is read-only or lacks this operation)
503The subsystem is not configured on this daemon

Error bodies use the error format.

Example

Request
curl -X PATCH "http://127.0.0.1:7385/settings" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"meshEnabled":false}'

Read one setting

GET/settings/{key}

Operation getSettingAuthBearer token

Secret keys read as null; providers[].apiKey as __redacted__.

Path parameters

NameTypeDescription
keyrequiredstring

Settings key

example: meshEnabled

Responses

StatusDescriptionBody
200ValueSettingValueResponse
keyrequiredstring
valuerequiredany

Any JSON value; null for secret keys

Errors 401 · 403 · 503
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
503The subsystem is not configured on this daemon

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/settings/meshEnabled" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"
Response 200
{
  "key": "meshEnabled",
  "value": true
}

Write one setting

PUT/settings/{key}

Operation putSettingAuthBearer token

Never writable here (403, no code): ownerMnemonic, runtimePrivateKey, runtimeEncPrivateKey, mcpOauthCredentials, trustedDaemonEncKeys, ownerDid, ownerEncPublicKey, runtimeDid, runtimeEncPublicKey, runtimeDelegation, legacyOwnerDids, legacyRuntimeDids, daemonRuntimeDid, daemonRuntimeDelegation, ownerDidSeedDerived. The owner identity changes only through /identity. A providers[].apiKey of __redacted__ keeps the stored key.

Path parameters

NameTypeDescription
keyrequiredstring

Settings key

example: meshEnabled

Request bodyapplication/json · SettingPutBody · required

FieldTypeDescription
valuerequiredany

Any JSON value

Responses

StatusDescriptionBody
200Stored valueSettingValueResponse
keyrequiredstring
valuerequiredany

Any JSON value; null for secret keys

Errors 400 · 401 · 403 · 405 · 503
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403A secret or identity settings key cannot be written over HTTP (setting_not_writable), or the request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)
405Not available on this daemon (the subsystem is read-only or lacks this operation)
503The subsystem is not configured on this daemon

Error bodies use the error format.

Example

Request
curl -X PUT "http://127.0.0.1:7385/settings/meshEnabled" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"value":true}'
Response 200
{
  "key": "meshEnabled",
  "value": true
}