레퍼런스로 건너뛰기

vault-http · v1

vault API

Jake의 Mac에 있는 파일과 표를 /v1로 다뤄요. 모든 호출은 이 브라우저에서 Mac으로 바로 가요. 이 페이지는 키도 데이터도 거치지 않아요.

openapi.json · Mac에 설치된 openapi.yaml

연결

어느 문으로 부를까요
확인하는 중…

ak_…(계정) 또는 ok_…(주인, tailnet 문). 이 탭에만 남고 다른 곳으로 보내지 않아요.

처음이라면 (에이전트도 같아요)

  1. register로 계정을 만들고 키를 받아요. 받은 키에는 아직 아무 권한이 없어요.
  2. request로 한 단계씩 요청해요. browse → list → read 순서이고, write는 따로 요청해요.
  3. Jake가 승인하면 그 범위만 열려요. 승인됐는지는 GET /v1/auth로 확인해요.
  4. 쓸 때는 읽을 때 받은 etag를 같이 보내요. 그 사이에 바뀌었으면 412로 막혀요.

레퍼런스

Index — 무엇이 있나

  • GET/v1no key

    What this server is; the only call without a key.

    curl 보기
    curl -sS 'https://jk-mac.tail79dafa.ts.net:8443/v1'
  • GET/v1/openapi.yamlno key

    This document, as installed.

    curl 보기
    curl -sS 'https://jk-mac.tail79dafa.ts.net:8443/v1/openapi.yaml'

Auth — 계정, 키, 권한

  • GET/v1/authany key

    The account behind this key, and its grants.

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS 'https://jk-mac.tail79dafa.ts.net:8443/v1/auth' \
      -H "Authorization: Bearer $VAULT_KEY"
  • POST/v1/authloginno key · the tailnet door · a login listed in admins

    이건 tailnet 문에서만 돼요. 위에서 문을 바꿔 주세요.

    응답 login → {key, expiresAt}

    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/auth' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"login"}'
  • POST/v1/authregisterno key
    요청 필드
    필드형식과 뜻
    params.id*string
    params.purpose*string

    응답 register → {id, key, status} (the key is shown once)

    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/auth' \
      -H 'Content-Type: application/json' \
      --data '{"action":"register","params":{"id":"claude-fashion-1","purpose":"Build a fashion table from my photos"}}'
  • POST/v1/authrequestany key
    요청 필드
    필드형식과 뜻
    params.resource*"file" | "table" | "meta"
    params.scope*string | string[]a path prefix matched by whole segments, or a list of them (any one)
    params.level"browse" | "list" | "read"
    params.writeboolean · 기본 false
    params.reason*string
    params.ttlDaysinteger 1–365

    응답 request / grant → {grant}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/auth' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"request","params":{"resource":"file","scope":"photos","level":"browse","reason":"Find the folder of today'\''s photos"}}'
  • POST/v1/authaccountsadmin key · the tailnet door

    이건 tailnet 문에서만 돼요. 위에서 문을 바꿔 주세요.

    응답 accounts → {accounts}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/auth' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"accounts"}'
  • POST/v1/authgrantadmin key · the tailnet door

    이건 tailnet 문에서만 돼요. 위에서 문을 바꿔 주세요.

    요청 필드
    필드형식과 뜻
    params.account*string
    params.indexinteger
    params.ttlDaysinteger 1–365
    params.resource"file" | "table" | "meta"
    params.scopestring | string[]a path prefix matched by whole segments, or a list of them (any one)
    params.level"browse" | "list" | "read"
    params.writeboolean

    응답 request / grant → {grant}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/auth' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"grant","params":{"account":"claude-fashion-1","index":0,"ttlDays":7}}'
  • POST/v1/authdenyadmin key · the tailnet door

    이건 tailnet 문에서만 돼요. 위에서 문을 바꿔 주세요.

    요청 필드
    필드형식과 뜻
    params.account*string
    params.index*integer

    응답 deny → {account, index, removed}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/auth' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"deny","params":{"account":"claude-fashion-1","index":0}}'
  • POST/v1/authdisableadmin key · the tailnet door

    이건 tailnet 문에서만 돼요. 위에서 문을 바꿔 주세요.

    요청 필드
    필드형식과 뜻
    params.account*string

    응답 disable / enable → {id, status}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/auth' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"disable","params":{"account":"claude-fashion-1"}}'
  • POST/v1/authenableadmin key · the tailnet door

    이건 tailnet 문에서만 돼요. 위에서 문을 바꿔 주세요.

    요청 필드
    필드형식과 뜻
    params.account*string

    응답 disable / enable → {id, status}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/auth' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"enable","params":{"account":"claude-fashion-1"}}'

Meta — 기기 상태

  • GET/v1/metaa meta grant (any level)

    The device — power, disks, the file index, backups. Needs a meta grant (any level).

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS 'https://jk-mac.tail79dafa.ts.net:8443/v1/meta' \
      -H "Authorization: Bearer $VAULT_KEY"

File — 파일

  • GET/v1/file/{path}read — or a signed link from link

    The bytes of one file. Needs read.

    A key, or a signed link from the link action (?exp=…&sig=…) for <img> and <video>, which cannot send headers.

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS 'https://jk-mac.tail79dafa.ts.net:8443/v1/file/photos/2026/10/06/IMG_0001.jpg' \
      -H "Authorization: Bearer $VAULT_KEY"
  • PUT/v1/file/{path}write

    Write the bytes of one file. Needs write.

    쓰기 방식
    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X PUT 'https://jk-mac.tail79dafa.ts.net:8443/v1/file/photos/2026/10/06/IMG_0001.jpg' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'If-None-Match: *' \
      --data-binary @'IMG_0001.jpg'
  • POST/v1/filefoldersbrowse
    요청 필드
    필드형식과 뜻
    params.path*string"" is the root
    params.depthinteger 1–4 · 기본 1

    응답 folders → {path, folders: [{path, count, bytes, mtime}]}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/file' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"folders","params":{"path":"photos","depth":2}}'
  • POST/v1/filelistlist
    요청 필드
    필드형식과 뜻
    params.path*string

    응답 list → {path, entries: [FileMeta]}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/file' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"list","params":{"path":"photos/2026/10/06"}}'
  • POST/v1/filefindlist
    요청 필드
    필드형식과 뜻
    params.path*stringsearched with every folder below it
    params.extstring[]
    params.namestringa substring of the file name
    params.sinceinteger
    params.untilinteger
    params.by"mtime" | "taken" · 기본 "mtime"taken falls back to mtime where unknown
    params.limitinteger 1–1000 · 기본 200

    응답 find → {results: [FileMeta], truncated}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/file' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"find","params":{"path":"photos","ext":[".jpg"],"by":"taken","since":1791241200}}'
  • POST/v1/filestatlist
    요청 필드
    필드형식과 뜻
    params.path*string (Path)vault-relative, no leading /, no segment starting with .

    응답 stat → FileMeta

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/file' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"stat","params":{"path":"photos/2026/10/06/IMG_0001.jpg"}}'
  • POST/v1/fileresolvelist
    요청 필드
    필드형식과 뜻
    params.names*string[]

    응답 resolve → {paths: {name: path|null}}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/file' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"resolve","params":{"names":["Siddhartha"]}}'
  • POST/v1/filesearchread
    요청 필드
    필드형식과 뜻
    params.q*string
    params.pathstring
    params.limitinteger 1–200 · 기본 50

    응답 search → {results: [{path, match, snippet?}]}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/file' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"search","params":{"q":"Siddhartha","limit":20}}'
  • POST/v1/filelinkread
    요청 필드
    필드형식과 뜻
    params.path*string (Path)vault-relative, no leading /, no segment starting with .
    params.ttlinteger 30–3600 · 기본 600

    응답 link → {url, expiresAt}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/file' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"link","params":{"path":"photos/2026/10/06/IMG_0001.jpg","ttl":600}}'
  • POST/v1/filemovewrite
    요청 필드
    필드형식과 뜻
    params.from*string (Path)vault-relative, no leading /, no segment starting with .
    params.to*string (Path)vault-relative, no leading /, no segment starting with .
    params.etagstring (ETag)

    응답 move → {from, to}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/file' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"move","params":{"from":"inbox/a.md","to":"notes/a.md"}}'
  • POST/v1/filemkdirwrite
    요청 필드
    필드형식과 뜻
    params.path*string (Path)vault-relative, no leading /, no segment starting with .

    응답 mkdir → {path}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/file' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"mkdir","params":{"path":"notes/2026"}}'
  • POST/v1/filedeletewrite
    요청 필드
    필드형식과 뜻
    params.path*string (Path)vault-relative, no leading /, no segment starting with .
    params.etag*string (ETag)

    응답 delete → {path, trashed}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/file' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"delete","params":{"path":"inbox/a.md","etag":"\"0000000000000000000000000000000000000000000000000000000000000000\""}}'

Table — 표

  • POST/v1/tabletablesbrowse

    응답 tables → {tables: [{scope, rows, errors, mtime}]}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/table' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"tables"}'
  • POST/v1/tableschemalist
    요청 필드
    필드형식과 뜻
    scope*string (TableScope)

    응답 schema → {schema, etag}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/table' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"schema","scope":"table/fashion"}'
  • POST/v1/tableidslist
    요청 필드
    필드형식과 뜻
    scope*string (TableScope)
    params.limitinteger 1–10000 · 기본 1000
    params.offsetinteger ≥ 0 · 기본 0

    응답 ids → {ids: [{id, mtime}], total}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/table' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"ids","scope":"table/fashion","params":{"limit":100}}'
  • POST/v1/tablequeryread
    요청 필드
    필드형식과 뜻
    scope*string (TableScope)
    params.whereobject{field: value}; a dotted field reaches into objects; an array field matches if any element does
    params.sortstringfield or -field
    params.limitinteger 0–1000 · 기본 100
    params.offsetinteger ≥ 0 · 기본 0

    응답 query → {rows: [Row], total, limit, offset, errors}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/table' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"query","scope":"table/fashion","params":{"where":{"kind":"top"},"sort":"-taken","limit":20}}'
  • POST/v1/tablegetread
    요청 필드
    필드형식과 뜻
    scope*string (TableScope)
    params.id*string (RowId)

    응답 get → Row

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/table' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"get","scope":"table/fashion","params":{"id":"row-1"}}'
  • POST/v1/tablecreatewrite
    요청 필드
    필드형식과 뜻
    scope*string (TableScope)
    params.schemaobjectA JSON Schema (2020-12 spelling) for one row. v1 checks these keywords and refuses a schema that uses any other (so a schema never silently means less than it says): type, properties, required, additionalProperties (boolean or schema), items, minItems, maxItems, enum, const, minimum, maximum, minLength, maxLength, pattern, anyOf; and, as annotations only, $schema, $id, title, description, default, examples, format.

    응답 create → {scope}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/table' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"create","scope":"table/fashion","params":{"schema":{"type":"object","required":["photo","kind"],"properties":{"photo":{"type":"string"},"kind":{"enum":["top","bottom","outer","shoes","accessory"]},"colors":{"type":"array","items":{"type":"string"}},"taken":{"type":"integer"}}}}}'
  • POST/v1/tableset_schemawrite
    요청 필드
    필드형식과 뜻
    scope*string (TableScope)
    params.schema*objectA JSON Schema (2020-12 spelling) for one row. v1 checks these keywords and refuses a schema that uses any other (so a schema never silently means less than it says): type, properties, required, additionalProperties (boolean or schema), items, minItems, maxItems, enum, const, minimum, maximum, minLength, maxLength, pattern, anyOf; and, as annotations only, $schema, $id, title, description, default, examples, format.
    params.etagstring (ETag)

    응답 set_schema → {etag}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/table' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"set_schema","scope":"table/fashion","params":{"schema":{"type":"object","required":["photo","kind"]},"etag":"\"0000000000000000000000000000000000000000000000000000000000000000\""}}'
  • POST/v1/tableinsertwrite
    요청 필드
    필드형식과 뜻
    scope*string (TableScope)
    params.data*any

    응답 insert → {id, etag}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/table' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"insert","scope":"table/fashion","params":{"data":{"photo":"photos/2026/10/06/IMG_0001.jpg","kind":"top","colors":["navy"],"taken":1791243000}}}'
  • POST/v1/tableputwrite
    요청 필드
    필드형식과 뜻
    scope*string (TableScope)
    params.id*string (RowId)
    params.data*any
    params.etagstring (ETag)
    params.createboolean

    응답 put → {id, etag, created}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/table' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"put","scope":"table/fashion","params":{"id":"row-1","data":{"photo":"photos/2026/10/06/IMG_0001.jpg","kind":"shoes"},"create":true}}'
  • POST/v1/tabledeletewrite
    요청 필드
    필드형식과 뜻
    scope*string (TableScope)
    params.id*string (RowId)
    params.etag*string (ETag)

    응답 delete → {id, trashed}

    키가 없어요. 401이 올 거예요.
    curl 보기
    curl -sS -X POST 'https://jk-mac.tail79dafa.ts.net:8443/v1/table' \
      -H "Authorization: Bearer $VAULT_KEY" \
      -H 'Content-Type: application/json' \
      --data '{"action":"delete","scope":"table/fashion","params":{"id":"row-1","etag":"\"0000000000000000000000000000000000000000000000000000000000000000\""}}'

오류

실패는 언제나 {status, message} 모양이에요. status로 분기하고, message는 사람이 읽는 말이라 바뀔 수 있어요.

오류 status와 HTTP 코드
statusHTTP
invalid_request400
unauthorized401
grant_required403
forbidden403
not_found404
conflict409
precondition_failed412
too_large413
misdirected421
precondition_required428
rate_limited429
internal_error500