Skip to content

API reference ​

The service exposes three HTTP surfaces on port 8000.

PrefixPurposeAuthentication
/WebUI static applicationNone
/apiTorznab XML endpointNone; apikey is accepted but not validated
/webapiSame-origin JSON configuration APINone

WebAPI endpoints ​

MethodPath200 responseHandled error statuses
GET/webapi/statusAggregate service status—
GET/webapi/settingsPublic schema-v1 settings—
PUT/webapi/settingsValidated effective public settings422 invalid body
GET/webapi/result-processingEffective preset and custom rules—
PUT/webapi/result-processingValidated effective preset and rules422 invalid body
GET/webapi/prowlarr/statusLive status, including remote failure detailsAlways 200
POST/webapi/prowlarr/test{ "connected": true, "error": null }400, 502
POST/webapi/prowlarr/indexerCreation or existing-indexer result400, 502

During the brief snapshot database switch, middleware can return HTTP 503 with Retry-After: 5 for any route before its normal handler runs.

GET /webapi/status ​

This endpoint probes PostgreSQL but does not contact Prowlarr. Its Prowlarr section contains the latest in-process summary from a focused Prowlarr operation, or null state before one has run.

FieldTypeMeaning
api_versionintegerWebAPI schema version; currently 1
application_versionstringFastAPI application version
database.connectedbooleanResult of the current database probe
updater.installed_versionstring or nullInstalled snapshot tag
updater.latest_versionstring or nullLast discovered remote tag
updater.enabledbooleanEffective automatic-update state
updater.updatingbooleanWhether an update is running
updater.maintenancebooleanWhether the database switch is in progress
updater.last_checkstring or nullISO-8601 timestamp
updater.next_checkstring or nullISO-8601 timestamp; null when disabled
updater.last_errorstring or nullLast updater error
result_processing.presetstringEffective preset
result_processing.custom_rule_countintegerNumber of configured rules, including disabled rules
prowlarr.configuredbooleanURL and API key are both effective
prowlarr.connectedboolean or nullCached connection result
prowlarr.indexer_installedboolean or nullCached installation result
prowlarr.errorstring or nullCached sanitized error

Settings ​

GET /webapi/settings and a successful PUT /webapi/settings return:

FieldType
schema_versioninteger 1
database_update.enabledboolean
database_update.interval_secondsinteger, 60–604800
result_processing.presetunfiltered, italian_preferred, italian_only, or custom
result_processing.custom_rulesarray
prowlarr.urlstring
prowlarr.indexer_urlstring
prowlarr.api_key_configuredboolean

PUT accepts an optional write-only prowlarr.api_key: omission preserves the persisted key, a non-empty string replaces it, and an empty string clears it. Validation or unknown fields return HTTP 422 with { "detail": "..." }. A successful full-settings update also reconfigures the updater and clears cached Prowlarr status.

Result processing ​

Both result-processing routes use this body:

json
{
  "preset": "italian_preferred",
  "custom_rules": []
}

GET returns the effective object. PUT returns the validated effective object; an invalid preset, rule, field, operator, action, value, or unknown field returns HTTP 422 with a detail string.

Prowlarr status ​

GET /webapi/prowlarr/status returns HTTP 200 with all four fields:

FieldTypeBehavior
configuredbooleanFalse unless URL and API key are effective
connectedboolean or nullNull when unconfigured; otherwise the live connection result
indexer_installedboolean or nullNull when unconfigured or status setup fails; otherwise the live endpoint match result
errorstring or nullSanitized specific failure or null

Normal remote failures remain status data rather than HTTP errors. For example:

json
{
  "configured": true,
  "connected": false,
  "indexer_installed": false,
  "error": "Unable to connect to Prowlarr"
}

Specific safe errors include connection, remote HTTP status, response-size, invalid-JSON, and invalid-schema failures. If an error contains the configured secret or traceback text, it is replaced with Prowlarr request failed.

Prowlarr commands ​

RouteSuccess body400502
POST /webapi/prowlarr/test{ "connected": true, "error": null }Prowlarr URL or API key missingRemote/client failure; { "detail": "Prowlarr request failed" }
POST /webapi/prowlarr/indexer{ "created": boolean, "already_installed": boolean, "indexer_id": integer or null }Prowlarr URL, API key, or Indexer URL missingSchema, test, list, or create failure; { "detail": "Prowlarr request failed" }

An already-installed indexer returns created: false and already_installed: true. A newly created indexer returns the inverse. The ID is null when Prowlarr does not provide an integer ID.

Secret behavior ​

Normal JSON reads never include the saved or environment-provided API key. GET /webapi/settings exposes only api_key_configured; status responses expose no key field. Prowlarr command errors always use the stable generic detail. Prowlarr status errors may retain a sanitized specific reason, but any reason containing the configured key or traceback text is replaced. See the configuration schema for replacement and clear rules.

Torznab ​

See Torznab capabilities for query and XML details.

Violarr was created and made possible in part through generative AI tools, under human direction and review.