Both answer without a token. Open them from a computer on the studio network, for example
http://192.168.1.50:3002/api/v2/docs.
The Reference pages below this one have a try-out panel: fill in your Core’s address and port (
core_host, core_port) and the token, and the call goes straight from your browser to the Core on your LAN. The Core allows calls from this site and from a local docs server (http://localhost:3333) through CORS. The Core serves plain HTTP, so a browser on this HTTPS site may still block the call as mixed content. If it does, use the same reference on the Core itself at http://<core>:3002/api/v2/docs, or run the docs locally.The reference page
/api/v2/docs lists every route per feature: methods, the JSON path, the plain-text path, whether it reads or controls, and its parameters. Read routes without parameters are links, so you can open them straight from the page.
The OpenAPI document
openapi.json holds both presentations of every route: the JSON route and its /plain twin. Control routes appear with GET and POST. The shared query parameters are on each operation: ?station= on station-scoped routes, and ?wait= and ?timeout= on control routes.
The document declares three ways to authenticate: deviceToken (Bearer), queryToken (?token=) and legacyBasic (Core v1’s EXTERNAL_APP header). The routes that need no token are marked as such.
The servers entry is the address you fetched the document from, so tools send their calls to the same Core.
The reference on this site
The Reference group in this section is generated from a copy of the OpenAPI document. It lists the JSONGET operation of every route, 77 in all, with its parameters. The same routes also answer POST (the control routes) and have a /plain twin; those are not listed again in the reference. See Routes and Plain-text routes for them.
The reference shows every v2 feature; the v1 routes are on Legacy routes. A Core lists only the features that are switched on for its studio, so its own openapi.json and /api/v2/docs can be shorter.