Skip to content
Area

Accounts

94 addresses. Not promised — they belong to the internals and can change with any release. If you need something to stay put, use the promised nineteen.

94 addresses

POST /api/auth/login may change

Sign in

Exchanges username or e-mail and password for an access token. The refresh token comes back as an HttpOnly cookie rather than in the body, so no script in the page can read it. Repeated failures slow the endpoint down deliberately.

Fields and shape

Request body

FieldType
usernamestring required
passwordstring required

Response

FieldType
access_tokenstring required
token_typestring
expires_innumber required

Response shape

{
  "access_token": "string",
  "token_type": "string",
  "expires_in": "number"
}

POST /api/auth/logout may change

Sign out of this browser

Ends the session of this browser on the server and clears the cookie. Afterwards no token of that session works any more - neither a copy of the cookie taken earlier nor the access token still in use. Without an authentication check, on purpose: anyone who wants to sign out should be able to, even if their access token expired long ago; only the session whose token comes with the request is ended. Other devices stay signed in - to end them all, see the sign-out-everywhere endpoint.

GET /api/auth/me may change

Your own account

Everything the calling account knows about itself: name, role, language, theme, quota settings and linked media-server accounts.

Fields and shape

Response

FieldType
idnumber required
usernamestring required
roleadmin | approver | user | child required
display_namestring or null required
emailstring or null required
email_verifiedboolean required
languagestring required
themestring required
is_activeboolean required
is_betreiberboolean
auto_approveboolean required
auto_approve_moviesboolean or null required
auto_approve_seriesboolean or null required
effective_auto_approveboolean required
effective_auto_approve_moviesboolean required
effective_auto_approve_seriesboolean required
can_approveboolean required
quota_movies_limitnumber required
quota_series_limitnumber required
storage_limit_gbnumber
quota_reset_attimestamp (ISO 8601) or null required
hausordnung_gelesen_amtimestamp (ISO 8601) or null
blocked_movie_profileslist of number required
blocked_series_profileslist of number required
fassung_rechtelist of FassungRechtOut
can_request_uhd_moviesboolean required
can_request_uhd_seriesboolean required
auto_approve_uhdboolean required
effective_auto_approve_uhdboolean required
blocked_movie_uhd_profileslist of number required
blocked_series_uhd_profileslist of number required
avatar_urlstring or null required
created_attimestamp (ISO 8601) required
last_login_attimestamp (ISO 8601) or null required
mail_download_completeboolean required
mail_request_pendingboolean required
mail_request_decidedboolean required
mail_feedbackboolean required
mail_ticketboolean required
mail_watchboolean required
mail_user_importedboolean required
mail_mediaserver_reconnectboolean required
mail_storageboolean required
mail_child_wishboolean required
mail_cleanupboolean required
push_download_completeboolean required
push_request_pendingboolean required
push_request_decidedboolean required
push_feedbackboolean required
push_ticketboolean required
push_watchboolean required
push_user_importedboolean required
push_mediaserver_reconnectboolean required
push_storageboolean required
push_child_wishboolean required
watchlist_connectedboolean required
watchlist_token_invalidboolean
mediaserver_providerstring or null required
mediaserver_usernamestring or null required
mediaserver_linkedboolean required
mediaserver_accountslist of VerknuepftesKonto
oidc_linkslist of OidcVerknuepfung
has_passwordboolean required
discover_regionstring or null required
agenumber or null required
rating_regionstring or null required
hide_unratedboolean required
can_manage_childrenboolean
parent_idnumber or null

Response shape

{
  "id": "number",
  "username": "string",
  "role": "admin | approver | user | child",
  "display_name": "string | null",
  "email": "string | null",
  "email_verified": "boolean",
  "language": "string",
  "theme": "string",
  "is_active": "boolean",
  "is_betreiber": "boolean",
  "auto_approve": "boolean",
  "auto_approve_movies": "boolean | null",
  "auto_approve_series": "boolean | null",
  "effective_auto_approve": "boolean"
}

PATCH /api/auth/me may change

Change your own account

Display name, language, region, theme and notification preferences. The username is not among them: it appears in requests, approvals and the Radarr/Sonarr labels, and changing it afterwards would tear those traces apart.

Fields and shape

Request body

FieldType
display_namestring or null
languagestring or null
themestring or null
mail_download_completeboolean or null
mail_request_pendingboolean or null
mail_request_decidedboolean or null
mail_feedbackboolean or null
mail_ticketboolean or null
mail_watchboolean or null
mail_user_importedboolean or null
mail_mediaserver_reconnectboolean or null
mail_storageboolean or null
mail_child_wishboolean or null
mail_cleanupboolean or null
push_download_completeboolean or null
push_request_pendingboolean or null
push_request_decidedboolean or null
push_feedbackboolean or null
push_ticketboolean or null
push_watchboolean or null
push_user_importedboolean or null
push_mediaserver_reconnectboolean or null
push_storageboolean or null
push_child_wishboolean or null
discover_regionstring or null

Response

FieldType
idnumber required
usernamestring required
roleadmin | approver | user | child required
display_namestring or null required
emailstring or null required
email_verifiedboolean required
languagestring required
themestring required
is_activeboolean required
is_betreiberboolean
auto_approveboolean required
auto_approve_moviesboolean or null required
auto_approve_seriesboolean or null required
effective_auto_approveboolean required
effective_auto_approve_moviesboolean required
effective_auto_approve_seriesboolean required
can_approveboolean required
quota_movies_limitnumber required
quota_series_limitnumber required
storage_limit_gbnumber
quota_reset_attimestamp (ISO 8601) or null required
hausordnung_gelesen_amtimestamp (ISO 8601) or null
blocked_movie_profileslist of number required
blocked_series_profileslist of number required
fassung_rechtelist of FassungRechtOut
can_request_uhd_moviesboolean required
can_request_uhd_seriesboolean required
auto_approve_uhdboolean required
effective_auto_approve_uhdboolean required
blocked_movie_uhd_profileslist of number required
blocked_series_uhd_profileslist of number required
avatar_urlstring or null required
created_attimestamp (ISO 8601) required
last_login_attimestamp (ISO 8601) or null required
mail_download_completeboolean required
mail_request_pendingboolean required
mail_request_decidedboolean required
mail_feedbackboolean required
mail_ticketboolean required
mail_watchboolean required
mail_user_importedboolean required
mail_mediaserver_reconnectboolean required
mail_storageboolean required
mail_child_wishboolean required
mail_cleanupboolean required
push_download_completeboolean required
push_request_pendingboolean required
push_request_decidedboolean required
push_feedbackboolean required
push_ticketboolean required
push_watchboolean required
push_user_importedboolean required
push_mediaserver_reconnectboolean required
push_storageboolean required
push_child_wishboolean required
watchlist_connectedboolean required
watchlist_token_invalidboolean
mediaserver_providerstring or null required
mediaserver_usernamestring or null required
mediaserver_linkedboolean required
mediaserver_accountslist of VerknuepftesKonto
oidc_linkslist of OidcVerknuepfung
has_passwordboolean required
discover_regionstring or null required
agenumber or null required
rating_regionstring or null required
hide_unratedboolean required
can_manage_childrenboolean
parent_idnumber or null

Response shape

{
  "id": "number",
  "username": "string",
  "role": "admin | approver | user | child",
  "display_name": "string | null",
  "email": "string | null",
  "email_verified": "boolean",
  "language": "string",
  "theme": "string",
  "is_active": "boolean",
  "is_betreiber": "boolean",
  "auto_approve": "boolean",
  "auto_approve_movies": "boolean | null",
  "auto_approve_series": "boolean | null",
  "effective_auto_approve": "boolean"
}

DELETE /api/auth/me/avatar may change

Remove your profile picture

Deletes the picture file and falls back to the generated initials.

Fields and shape

Response

FieldType
idnumber required
usernamestring required
roleadmin | approver | user | child required
display_namestring or null required
emailstring or null required
email_verifiedboolean required
languagestring required
themestring required
is_activeboolean required
is_betreiberboolean
auto_approveboolean required
auto_approve_moviesboolean or null required
auto_approve_seriesboolean or null required
effective_auto_approveboolean required
effective_auto_approve_moviesboolean required
effective_auto_approve_seriesboolean required
can_approveboolean required
quota_movies_limitnumber required
quota_series_limitnumber required
storage_limit_gbnumber
quota_reset_attimestamp (ISO 8601) or null required
hausordnung_gelesen_amtimestamp (ISO 8601) or null
blocked_movie_profileslist of number required
blocked_series_profileslist of number required
fassung_rechtelist of FassungRechtOut
can_request_uhd_moviesboolean required
can_request_uhd_seriesboolean required
auto_approve_uhdboolean required
effective_auto_approve_uhdboolean required
blocked_movie_uhd_profileslist of number required
blocked_series_uhd_profileslist of number required
avatar_urlstring or null required
created_attimestamp (ISO 8601) required
last_login_attimestamp (ISO 8601) or null required
mail_download_completeboolean required
mail_request_pendingboolean required
mail_request_decidedboolean required
mail_feedbackboolean required
mail_ticketboolean required
mail_watchboolean required
mail_user_importedboolean required
mail_mediaserver_reconnectboolean required
mail_storageboolean required
mail_child_wishboolean required
mail_cleanupboolean required
push_download_completeboolean required
push_request_pendingboolean required
push_request_decidedboolean required
push_feedbackboolean required
push_ticketboolean required
push_watchboolean required
push_user_importedboolean required
push_mediaserver_reconnectboolean required
push_storageboolean required
push_child_wishboolean required
watchlist_connectedboolean required
watchlist_token_invalidboolean
mediaserver_providerstring or null required
mediaserver_usernamestring or null required
mediaserver_linkedboolean required
mediaserver_accountslist of VerknuepftesKonto
oidc_linkslist of OidcVerknuepfung
has_passwordboolean required
discover_regionstring or null required
agenumber or null required
rating_regionstring or null required
hide_unratedboolean required
can_manage_childrenboolean
parent_idnumber or null

Response shape

{
  "id": "number",
  "username": "string",
  "role": "admin | approver | user | child",
  "display_name": "string | null",
  "email": "string | null",
  "email_verified": "boolean",
  "language": "string",
  "theme": "string",
  "is_active": "boolean",
  "is_betreiber": "boolean",
  "auto_approve": "boolean",
  "auto_approve_movies": "boolean | null",
  "auto_approve_series": "boolean | null",
  "effective_auto_approve": "boolean"
}

POST /api/auth/me/avatar may change

Upload a profile picture

Accepts PNG, JPEG, GIF and WebP. The image is scaled down and re-encoded on the server, so what ends up stored is not the file that was sent.

Fields and shape

Response

FieldType
idnumber required
usernamestring required
roleadmin | approver | user | child required
display_namestring or null required
emailstring or null required
email_verifiedboolean required
languagestring required
themestring required
is_activeboolean required
is_betreiberboolean
auto_approveboolean required
auto_approve_moviesboolean or null required
auto_approve_seriesboolean or null required
effective_auto_approveboolean required
effective_auto_approve_moviesboolean required
effective_auto_approve_seriesboolean required
can_approveboolean required
quota_movies_limitnumber required
quota_series_limitnumber required
storage_limit_gbnumber
quota_reset_attimestamp (ISO 8601) or null required
hausordnung_gelesen_amtimestamp (ISO 8601) or null
blocked_movie_profileslist of number required
blocked_series_profileslist of number required
fassung_rechtelist of FassungRechtOut
can_request_uhd_moviesboolean required
can_request_uhd_seriesboolean required
auto_approve_uhdboolean required
effective_auto_approve_uhdboolean required
blocked_movie_uhd_profileslist of number required
blocked_series_uhd_profileslist of number required
avatar_urlstring or null required
created_attimestamp (ISO 8601) required
last_login_attimestamp (ISO 8601) or null required
mail_download_completeboolean required
mail_request_pendingboolean required
mail_request_decidedboolean required
mail_feedbackboolean required
mail_ticketboolean required
mail_watchboolean required
mail_user_importedboolean required
mail_mediaserver_reconnectboolean required
mail_storageboolean required
mail_child_wishboolean required
mail_cleanupboolean required
push_download_completeboolean required
push_request_pendingboolean required
push_request_decidedboolean required
push_feedbackboolean required
push_ticketboolean required
push_watchboolean required
push_user_importedboolean required
push_mediaserver_reconnectboolean required
push_storageboolean required
push_child_wishboolean required
watchlist_connectedboolean required
watchlist_token_invalidboolean
mediaserver_providerstring or null required
mediaserver_usernamestring or null required
mediaserver_linkedboolean required
mediaserver_accountslist of VerknuepftesKonto
oidc_linkslist of OidcVerknuepfung
has_passwordboolean required
discover_regionstring or null required
agenumber or null required
rating_regionstring or null required
hide_unratedboolean required
can_manage_childrenboolean
parent_idnumber or null

Response shape

{
  "id": "number",
  "username": "string",
  "role": "admin | approver | user | child",
  "display_name": "string | null",
  "email": "string | null",
  "email_verified": "boolean",
  "language": "string",
  "theme": "string",
  "is_active": "boolean",
  "is_betreiber": "boolean",
  "auto_approve": "boolean",
  "auto_approve_movies": "boolean | null",
  "auto_approve_series": "boolean | null",
  "effective_auto_approve": "boolean"
}

PUT /api/auth/me/email may change

Change your own e-mail address

The new address only counts as confirmed once the link in the mail has been clicked - otherwise anyone could enter somebody else's address. Until then the old one stays in force for password resets.

Fields and shape

Request body

FieldType
emailstring required

Response

FieldType
idnumber required
usernamestring required
roleadmin | approver | user | child required
display_namestring or null required
emailstring or null required
email_verifiedboolean required
languagestring required
themestring required
is_activeboolean required
is_betreiberboolean
auto_approveboolean required
auto_approve_moviesboolean or null required
auto_approve_seriesboolean or null required
effective_auto_approveboolean required
effective_auto_approve_moviesboolean required
effective_auto_approve_seriesboolean required
can_approveboolean required
quota_movies_limitnumber required
quota_series_limitnumber required
storage_limit_gbnumber
quota_reset_attimestamp (ISO 8601) or null required
hausordnung_gelesen_amtimestamp (ISO 8601) or null
blocked_movie_profileslist of number required
blocked_series_profileslist of number required
fassung_rechtelist of FassungRechtOut
can_request_uhd_moviesboolean required
can_request_uhd_seriesboolean required
auto_approve_uhdboolean required
effective_auto_approve_uhdboolean required
blocked_movie_uhd_profileslist of number required
blocked_series_uhd_profileslist of number required
avatar_urlstring or null required
created_attimestamp (ISO 8601) required
last_login_attimestamp (ISO 8601) or null required
mail_download_completeboolean required
mail_request_pendingboolean required
mail_request_decidedboolean required
mail_feedbackboolean required
mail_ticketboolean required
mail_watchboolean required
mail_user_importedboolean required
mail_mediaserver_reconnectboolean required
mail_storageboolean required
mail_child_wishboolean required
mail_cleanupboolean required
push_download_completeboolean required
push_request_pendingboolean required
push_request_decidedboolean required
push_feedbackboolean required
push_ticketboolean required
push_watchboolean required
push_user_importedboolean required
push_mediaserver_reconnectboolean required
push_storageboolean required
push_child_wishboolean required
watchlist_connectedboolean required
watchlist_token_invalidboolean
mediaserver_providerstring or null required
mediaserver_usernamestring or null required
mediaserver_linkedboolean required
mediaserver_accountslist of VerknuepftesKonto
oidc_linkslist of OidcVerknuepfung
has_passwordboolean required
discover_regionstring or null required
agenumber or null required
rating_regionstring or null required
hide_unratedboolean required
can_manage_childrenboolean
parent_idnumber or null

Response shape

{
  "id": "number",
  "username": "string",
  "role": "admin | approver | user | child",
  "display_name": "string | null",
  "email": "string | null",
  "email_verified": "boolean",
  "language": "string",
  "theme": "string",
  "is_active": "boolean",
  "is_betreiber": "boolean",
  "auto_approve": "boolean",
  "auto_approve_movies": "boolean | null",
  "auto_approve_series": "boolean | null",
  "effective_auto_approve": "boolean"
}

POST /api/auth/me/password may change

Change your own password

Changes the password and signs out every other device. Since 0.21 any token older than password_changed_at is refused, so a copy somebody made of your session stops working the moment you change it.

Fields and shape

Request body

FieldType
current_passwordstring required
new_passwordstring required

Response

FieldType
access_tokenstring required
token_typestring
expires_innumber required

Response shape

{
  "access_token": "string",
  "token_type": "string",
  "expires_in": "number"
}

POST /api/auth/me/resend-verification may change

Send the confirmation mail again

Requests a fresh confirmation mail for an address that has not been confirmed yet.

Fields and shape

Response

FieldType
sentboolean required
errorstring or null

Response shape

{
  "sent": "boolean",
  "error": "string | null"
}

GET /api/auth/me/schluessel may change

Your own API tokens

Lists the tokens belonging to the calling account - name, preview, whether it may only read, when it expires and when it was last used. Never the token itself; that exists once, at creation.

Fields and shape

Response

FieldType
idnumber required
namestring required
vorschaustring required
nur_lesenboolean required
created_attimestamp (ISO 8601) required
expires_attimestamp (ISO 8601) or null required
last_used_attimestamp (ISO 8601) or null required
rueckkanalstring or null
rueckkanal_bereitboolean

Response shape

[
  {
    "id": "number",
    "name": "string",
    "vorschau": "string",
    "nur_lesen": "boolean",
    "created_at": "ISO 8601",
    "expires_at": "ISO 8601 | null",
    "last_used_at": "ISO 8601 | null",
    "rueckkanal": "string | null",
    "rueckkanal_bereit": "boolean"
  }
]

POST /api/auth/me/schluessel may change

Create an API token

⚠️ The plain text appears in this one response and nowhere else. Afterwards only a checksum remains, and not even an administrator can look it up. A token inherits the rights of the account it belongs to; nur_lesen restricts it to GET requests. Child accounts cannot create tokens.

Fields and shape

Request body

FieldType
namestring required
nur_lesenboolean
tagenumber or null

Response

FieldType
idnumber required
namestring required
vorschaustring required
nur_lesenboolean required
created_attimestamp (ISO 8601) required
expires_attimestamp (ISO 8601) or null required
last_used_attimestamp (ISO 8601) or null required
rueckkanalstring or null
rueckkanal_bereitboolean
schluesselstring required

Response shape

{
  "id": "number",
  "name": "string",
  "vorschau": "string",
  "nur_lesen": "boolean",
  "created_at": "ISO 8601",
  "expires_at": "ISO 8601 | null",
  "last_used_at": "ISO 8601 | null",
  "rueckkanal": "string | null",
  "rueckkanal_bereit": "boolean",
  "schluessel": "string"
}

DELETE /api/auth/me/schluessel/{schluessel_id} may change

Revoke one of your tokens

Takes effect immediately - anything using that token is locked out from the next request onwards. You can only revoke your own; an administrator can see foreign tokens but not switch them off.

Fields and shape

Parameters

schluessel_idnumber path required

DELETE /api/auth/me/schluessel/{schluessel_id}/rueckkanal may change

Stop Nexview calling that integration back

The key stays valid. Only the callback address goes away, so the integration keeps working but has to ask for changes instead of being told about them. Use this when a Home Assistant moved or was reinstalled and its old address no longer answers.

Fields and shape

Parameters

schluessel_idnumber path required

POST /api/auth/me/ueberall-abmelden may change

Sign out everywhere

Ends every session of this account on every device, including the one making the call, without changing the password. ⚠️ The way out that did not exist before 0.22. Ordinary sign-out only ends the session of this browser; a session on another device, one you no longer have in hand, is only reached from here.

Fields and shape

Response

FieldType
access_tokenstring required
token_typestring
expires_innumber required

Response shape

{
  "access_token": "string",
  "token_type": "string",
  "expires_in": "number"
}

GET /api/auth/oidc/{slug}/callback may change

Return from a provider set up before 1.1

The redirect address providers knew until Nexview 1.0.1. Entries carried over from then keep it as their own; it leads to the same return.

Fields and shape

Parameters

slugstring path required

POST /api/auth/refresh may change

Renew the access token

The refresh token is read from the HttpOnly cookie, not from the request body. The new pair belongs to the same session, so signing out later ends it together with every earlier copy. Tokens from before 1.0.0 carry no session and are refused; those clients sign in once.

Fields and shape

Response

FieldType
access_tokenstring required
token_typestring
expires_innumber required

Response shape

{
  "access_token": "string",
  "token_type": "string",
  "expires_in": "number"
}

GET /api/children may change

Your own child accounts

The child profiles belonging to the calling account. Anyone without children gets an empty list. Child accounts are not accounts of their own: they are sub-profiles of a parent, and everything they cause runs against the parent's quota.

Fields and shape

Response

FieldType
idnumber required
usernamestring required
display_namestring or null required
agenumber or null required
is_activeboolean required
languagestring required
child_trailersboolean
genreslist of string required
created_attimestamp (ISO 8601) required
last_login_attimestamp (ISO 8601) or null required

Response shape

[
  {
    "id": "number",
    "username": "string",
    "display_name": "string | null",
    "age": "number | null",
    "is_active": "boolean",
    "language": "string",
    "child_trailers": "boolean",
    "genres": [
      "string"
    ],
    "created_at": "ISO 8601",
    "last_login_at": "ISO 8601 | null"
  }
]

POST /api/children may change

Create a child profile

Needs permission from an administrator first. The child gets its own sign-in and its own set of enabled categories, but no media-server link and no quota of its own.

Fields and shape

Request body

FieldType
usernamestring required
passwordstring required
agenumber required
display_namestring or null
genreslist of string or null
child_trailersboolean
languagestring or null

Response

FieldType
idnumber required
usernamestring required
display_namestring or null required
agenumber or null required
is_activeboolean required
languagestring required
child_trailersboolean
genreslist of string required
created_attimestamp (ISO 8601) required
last_login_attimestamp (ISO 8601) or null required

Response shape

{
  "id": "number",
  "username": "string",
  "display_name": "string | null",
  "age": "number | null",
  "is_active": "boolean",
  "language": "string",
  "child_trailers": "boolean",
  "genres": [
    "string"
  ],
  "created_at": "ISO 8601",
  "last_login_at": "ISO 8601 | null"
}

GET /api/children/genres may change

The categories a child can be given

The selectable categories in their fixed order. The interface fetches them here rather than listing them itself - otherwise there would be two lists that drift apart.

POST /api/children/request-permission may change

Ask to be allowed child profiles

A button, not a form: the text is fixed, so nobody has to invent one. Lands as a ticket with the administrators.

GET /api/children/wishes may change

Wishes waiting for your decision

What the children of the calling account have wished for and nobody has decided yet.

Fields and shape

Response

FieldType
idnumber required
child_idnumber required
child_namestring required
media_typestring required
tmdb_idnumber required
titlestring required
poster_pathstring or null required
in_my_subscriptionslist of string
release_datestring or null required
created_atstring required

Response shape

[
  {
    "id": "number",
    "child_id": "number",
    "child_name": "string",
    "media_type": "string",
    "tmdb_id": "number",
    "title": "string",
    "poster_path": "string | null",
    "in_my_subscriptions": [
      "string"
    ],
    "release_date": "string | null",
    "created_at": "string"
  }
]

POST /api/children/wishes/{wish_id}/decline may change

Turn down a wish

The child is told, and the wish is closed. Nothing is requested.

Fields and shape

Parameters

wish_idnumber path required

Request body

FieldType
notestring or null

POST /api/children/wishes/{wish_id}/release may change

Turn a wish into a request

The wish becomes a request in the parent's name. The title is fetched from their point of view: it is their request, against their quota and their age settings.

Fields and shape

Parameters

wish_idnumber path required

Request body

FieldType
quality_profile_idnumber or null
root_folder_pathstring or null
seasonnumber or null
episodeslist of number or null
monitor_futureboolean
fassungstring or null
tierstandard | uhd

Response

FieldType
idnumber required
media_typemovie | tv required
fassungstring or null required
tierstandard | uhd required
tmdb_idnumber required
titlestring required
poster_pathstring or null required
release_datestring or null required
statuspending_approval | approved | searching | downloaded | rejected | failed | cancelled | deleted | deferred required
quality_profile_idnumber or null required
quality_profile_uhdboolean
root_folder_pathstring or null required
seasonnumber or null required
episodeslist of number or null
from_watchlistboolean required
arr_linkedboolean
requested_attimestamp (ISO 8601) required
approved_attimestamp (ISO 8601) or null required
completed_attimestamp (ISO 8601) or null required
approved_by_namestring or null
last_checked_attimestamp (ISO 8601) or null
laedt_fortschrittnumber or null
laedt_seittimestamp (ISO 8601) or null
rejection_reasonstring or null required
regel_namestring or null
darf_trotzdem_fragenboolean
trotzdem_gefragtboolean
error_messagestring or null required
error_detailobject or null
ratingnumber or null required
feedbackstring or null required
rated_attimestamp (ISO 8601) or null required
rating_outdatedboolean
feedback_replystring or null required
replied_attimestamp (ISO 8601) or null required

Response shape

{
  "id": "number",
  "media_type": "movie | tv",
  "fassung": "string | null",
  "tier": "standard | uhd",
  "tmdb_id": "number",
  "title": "string",
  "poster_path": "string | null",
  "release_date": "string | null",
  "status": "pending_approval | approved | searching | downloaded | rejected | failed | cancelled | deleted | deferred",
  "quality_profile_id": "number | null",
  "quality_profile_uhd": "boolean",
  "root_folder_path": "string | null",
  "season": "number | null",
  "episodes": [
    "number"
  ]
}

DELETE /api/children/{child_id} may change

Delete a child profile

Removes the profile and its sign-in. Requests already made in the parent's name are unaffected - they were never the child's.

Fields and shape

Parameters

child_idnumber path required

PATCH /api/children/{child_id} may change

Change a child profile

Display name, enabled categories and age limit.

Fields and shape

Parameters

child_idnumber path required

Request body

FieldType
display_namestring or null
agenumber or null
is_activeboolean or null
genreslist of string or null
child_trailersboolean or null
languagestring or null

Response

FieldType
idnumber required
usernamestring required
display_namestring or null required
agenumber or null required
is_activeboolean required
languagestring required
child_trailersboolean
genreslist of string required
created_attimestamp (ISO 8601) required
last_login_attimestamp (ISO 8601) or null required

Response shape

{
  "id": "number",
  "username": "string",
  "display_name": "string | null",
  "age": "number | null",
  "is_active": "boolean",
  "language": "string",
  "child_trailers": "boolean",
  "genres": [
    "string"
  ],
  "created_at": "ISO 8601",
  "last_login_at": "ISO 8601 | null"
}

POST /api/children/{child_id}/password may change

Set a child's password

The parent sets it directly. A child has no e-mail address, so there is no reset link to send.

Fields and shape

Parameters

child_idnumber path required

Request body

FieldType
passwordstring required

Response

FieldType
idnumber required
usernamestring required
display_namestring or null required
agenumber or null required
is_activeboolean required
languagestring required
child_trailersboolean
genreslist of string required
created_attimestamp (ISO 8601) required
last_login_attimestamp (ISO 8601) or null required

Response shape

{
  "id": "number",
  "username": "string",
  "display_name": "string | null",
  "age": "number | null",
  "is_active": "boolean",
  "language": "string",
  "child_trailers": "boolean",
  "genres": [
    "string"
  ],
  "created_at": "ISO 8601",
  "last_login_at": "ISO 8601 | null"
}

GET /api/children/{child_id}/preview/backdrops may change

Preview: the child's backdrops

What the child sees behind its start page. Part of the preview, so a parent can check what they have enabled without signing in as the child.

Fields and shape

Parameters

child_idnumber path required

GET /api/children/{child_id}/preview/categories may change

Preview: the child's start page

The start page exactly as this child would see it - one tile per enabled category.

Fields and shape

Parameters

child_idnumber path required
media_typestring query

Response

FieldType
rubrikstring required
bilderlist of string required

Response shape

[
  {
    "rubrik": "string",
    "bilder": [
      "string"
    ]
  }
]

GET /api/children/{child_id}/preview/rubrik/{rubrik} may change

Preview: one category

Everything in one category, as the child would see it. The category is checked against what this child is allowed.

Fields and shape

Parameters

child_idnumber path required
rubrikstring path required
media_typestring query
pagenumber query

Response

FieldType
verfuegbarlist of MediaItem required
wuenschbarlist of MediaItem required
gewuenschtlist of number

Response shape

{
  "verfuegbar": [
    {
      "media_type": "movie | tv",
      "tmdb_id": "number",
      "tvdb_id": "number | null",
      "title": "string",
      "original_title": "string | null",
      "overview": "string",
      "poster_url": "string | null",
      "backdrop_url": "string | null",
      "release_date": "string | null",
      "vote_average": "number",
      "vote_count": "number",
      "genres": [
        "string"
      ],
      "genre_ids": [
        "number"
      ],
      "runtime_minutes": "number | null"
    }
  ],
  "wuenschbar": [
    {
      "media_type": "movie | tv",
      "tmdb_id": "number",
      "tvdb_id": "number | null",
      "title": "string",
      "original_title": "string | null",
      "overview": "string",
      "poster_url": "string | null",
      "backdrop_url": "string | null",
      "release_date": "string | null",
      "vote_average": "number",
      "vote_count": "number",
      "genres": [
        "string"
      ],
      "genre_ids": [
        "number"
      ],
      "runtime_minutes": "number | null"
    }
  ],
  "gewuenscht": [
    "number"
  ]
}

GET /api/children/{child_id}/preview/title/{media_type}/{tmdb_id} may change

Preview: one title

A single title exactly as the child would see it, including the category check.

Fields and shape

Parameters

child_idnumber path required
media_typestring path required
tmdb_idnumber path required

Response

FieldType
media_typemovie | tv required
tmdb_idnumber required
tvdb_idnumber or null
titlestring required
original_titlestring or null
overviewstring
poster_urlstring or null
backdrop_urlstring or null
release_datestring or null
vote_averagenumber
vote_countnumber
genreslist of string
genre_idslist of number
runtime_minutesnumber or null
certificationstring or null
original_languagestring or null
origin_countrylist of string
seasonslist of SeasonInfo
statusstring
status_uhdstring or null
fassungenlist of FassungAchse
watchedboolean
watched_onlist of string
watched_not_onlist of string
pathstring or null
path_uhdstring or null
uhd_in_standardboolean
taglinestring
homepagestring or null
status_textstring
original_countrylist of string
spoken_languageslist of string
budgetnumber or null
revenuenumber or null
studioslist of NamedRef
keywordslist of NamedRef
trailerTrailer or null
watchWatchProviders or null
in_my_subscriptionslist of string
watchingboolean
requested_by_meboolean
status_unconfirmedboolean
status_refusedboolean
my_feedbackMeineRueckmeldung or null
open_ticketboolean
castlist of CastMember
crewlist of CrewMember
recommendationslist of MediaItem
collectionMovieCollection or null
seasons_totalnumber or null
episodes_totalnumber or null
series_statusstring
networkslist of NamedRef

Response shape

{
  "media_type": "movie | tv",
  "tmdb_id": "number",
  "tvdb_id": "number | null",
  "title": "string",
  "original_title": "string | null",
  "overview": "string",
  "poster_url": "string | null",
  "backdrop_url": "string | null",
  "release_date": "string | null",
  "vote_average": "number",
  "vote_count": "number",
  "genres": [
    "string"
  ],
  "genre_ids": [
    "number"
  ],
  "runtime_minutes": "number | null"
}

GET /api/kids/backdrops may change

Backdrops for the start page

Images for the background of the children's view.

GET /api/kids/categories may change

The children's start page

One tile per enabled category. Categories first, titles second - so a child sees what things are about instead of walking into a wall of posters.

Fields and shape

Parameters

media_typemovie | tv query

Response

FieldType
rubrikstring required
bilderlist of string required

Response shape

[
  {
    "rubrik": "string",
    "bilder": [
      "string"
    ]
  }
]

GET /api/kids/rubrik/{rubrik} may change

Everything in one category

The whole category at once rather than a sideways-scrolling row. ⚠️ The category is checked: otherwise one that was never enabled could be requested through the address bar.

Fields and shape

Parameters

rubrikstring path required
media_typemovie | tv query
pagenumber query

Response

FieldType
verfuegbarlist of MediaItem required
wuenschbarlist of MediaItem required
gewuenschtlist of number required

Response shape

{
  "verfuegbar": [
    {
      "media_type": "movie | tv",
      "tmdb_id": "number",
      "tvdb_id": "number | null",
      "title": "string",
      "original_title": "string | null",
      "overview": "string",
      "poster_url": "string | null",
      "backdrop_url": "string | null",
      "release_date": "string | null",
      "vote_average": "number",
      "vote_count": "number",
      "genres": [
        "string"
      ],
      "genre_ids": [
        "number"
      ],
      "runtime_minutes": "number | null"
    }
  ],
  "wuenschbar": [
    {
      "media_type": "movie | tv",
      "tmdb_id": "number",
      "tvdb_id": "number | null",
      "title": "string",
      "original_title": "string | null",
      "overview": "string",
      "poster_url": "string | null",
      "backdrop_url": "string | null",
      "release_date": "string | null",
      "vote_average": "number",
      "vote_count": "number",
      "genres": [
        "string"
      ],
      "genre_ids": [
        "number"
      ],
      "runtime_minutes": "number | null"
    }
  ],
  "gewuenscht": [
    "number"
  ]
}

GET /api/kids/title/{media_type}/{tmdb_id} may change

One title for a child

A single title with its trailer and nothing else. ⚠️ The category is checked here too, not only when listing: otherwise a blocked title could be reached straight through the address bar.

Fields and shape

Parameters

media_typemovie | tv path required
tmdb_idnumber path required

Response

FieldType
media_typemovie | tv required
tmdb_idnumber required
tvdb_idnumber or null
titlestring required
original_titlestring or null
overviewstring
poster_urlstring or null
backdrop_urlstring or null
release_datestring or null
vote_averagenumber
vote_countnumber
genreslist of string
genre_idslist of number
runtime_minutesnumber or null
certificationstring or null
original_languagestring or null
origin_countrylist of string
seasonslist of SeasonInfo
statusstring
status_uhdstring or null
fassungenlist of FassungAchse
watchedboolean
watched_onlist of string
watched_not_onlist of string
pathstring or null
path_uhdstring or null
uhd_in_standardboolean
taglinestring
homepagestring or null
status_textstring
original_countrylist of string
spoken_languageslist of string
budgetnumber or null
revenuenumber or null
studioslist of NamedRef
keywordslist of NamedRef
trailerTrailer or null
watchWatchProviders or null
in_my_subscriptionslist of string
watchingboolean
requested_by_meboolean
status_unconfirmedboolean
status_refusedboolean
my_feedbackMeineRueckmeldung or null
open_ticketboolean
castlist of CastMember
crewlist of CrewMember
recommendationslist of MediaItem
collectionMovieCollection or null
seasons_totalnumber or null
episodes_totalnumber or null
series_statusstring
networkslist of NamedRef

Response shape

{
  "media_type": "movie | tv",
  "tmdb_id": "number",
  "tvdb_id": "number | null",
  "title": "string",
  "original_title": "string | null",
  "overview": "string",
  "poster_url": "string | null",
  "backdrop_url": "string | null",
  "release_date": "string | null",
  "vote_average": "number",
  "vote_count": "number",
  "genres": [
    "string"
  ],
  "genre_ids": [
    "number"
  ],
  "runtime_minutes": "number | null"
}

GET /api/kids/wishes may change

The child's own wishes

What this child has wished for and what became of each wish.

Fields and shape

Response

FieldType
idnumber required
media_typestring required
tmdb_idnumber required
titlestring required
poster_pathstring or null required
release_datestring or null required
statestring required
decline_notestring or null required
created_atstring required

Response shape

[
  {
    "id": "number",
    "media_type": "string",
    "tmdb_id": "number",
    "title": "string",
    "poster_path": "string | null",
    "release_date": "string | null",
    "state": "string",
    "decline_note": "string | null",
    "created_at": "string"
  }
]

POST /api/kids/wishes may change

Wish for something

The title is fetched from TMDB again here, with this child's settings: a blocked title fails the age check at that point rather than after the parent has already seen it.

Fields and shape

Request body

FieldType
media_typemovie | tv required
tmdb_idnumber required

Response

FieldType
idnumber required
media_typestring required
tmdb_idnumber required
titlestring required
poster_pathstring or null required
release_datestring or null required
statestring required
decline_notestring or null required
created_atstring required

Response shape

{
  "id": "number",
  "media_type": "string",
  "tmdb_id": "number",
  "title": "string",
  "poster_path": "string | null",
  "release_date": "string | null",
  "state": "string",
  "decline_note": "string | null",
  "created_at": "string"
}

GET /api/oidc/admin/blocks may change

List blocked identities

Identities blocked from signing in again - created when an account is deleted. Without this list a block would be forever.

Fields and shape

Response

FieldType
idnumber required
issuerstring required
displaystring or null

Response shape

[
  {
    "id": "number",
    "issuer": "string",
    "display": "string | null"
  }
]

DELETE /api/oidc/admin/blocks/{block_id} may change

Lift a block

Afterwards that identity may sign in again - and, where enabled, get an account.

Fields and shape

Parameters

block_idnumber path required

GET /api/oidc/admin/providers may change

List the sign-in providers

Every entry with its settings, the redirect address to register at the provider and how many accounts are linked. The client secret never leaves the server - the list only says whether one is set.

POST /api/oidc/admin/providers may change

Add a sign-in provider

Name on the button, short name, issuer, client id and secret, scopes and the switches. The issuer is checked by discovery before anything is stored. New people get no account unless that switch is on.

Fields and shape

Request body

FieldType
labelstring required
slugstring
issuerstring required
client_idstring required
client_secretstring
scopesstring
enabledboolean
auto_createboolean
trusts_second_factorboolean

PUT /api/oidc/admin/providers/order may change

Order the sign-in providers

The order of the buttons on the sign-in page.

Fields and shape

Request body

FieldType
idslist of number required

DELETE /api/oidc/admin/providers/{provider_id} may change

Remove a sign-in provider

Removes the entry with its links. Refused (403) when the operator would be locked out by somebody else.

Fields and shape

Parameters

provider_idnumber path required

PUT /api/oidc/admin/providers/{provider_id} may change

Save a sign-in provider

Everything but the short name. An empty client secret keeps the stored one. Another issuer is another provider: the links of this entry go (dropped tells how many).

Fields and shape

Parameters

provider_idnumber path required

Request body

FieldType
labelstring required
slugstring
issuerstring required
client_idstring required
client_secretstring
scopesstring
enabledboolean
auto_createboolean
trusts_second_factorboolean

GET /api/oidc/admin/providers/{provider_id}/impact may change

What a change or removal would cost

How many accounts would have to link again with this issuer, how many lose their link on removal, and for how many that is the only way in.

Fields and shape

Parameters

provider_idnumber path required
issuerstring query

GET /api/oidc/authentik/address may change

The public address as the authentik card sees it

The public address, the address this request arrived under, what a proxy said, the redirect address authentik would get and whether it still knows an older one.

POST /api/oidc/authentik/address may change

Save the public address

Use it only in the authentik card. Answers 409 public_url_change when a provider knows the old redirect address, until confirm is true.

Fields and shape

Request body

FieldType
public_urlstring required
confirmboolean

GET /api/oidc/authentik/blueprint may change

Download the authentik blueprint

nexview-authentik.yaml with the same objects the button creates. Needs a public address (409 public_url_needed without one).

POST /api/oidc/authentik/setup may change

Set up authentik in one step

Creates or updates signing key, scope mappings, provider and application in authentik with the given API token and fills in the entry here. Always answers 200 with the steps that ran, a failed one with its reason. The token is used for this run only and never stored.

Fields and shape

Request body

FieldType
urlstring required
tokenstring required
confirm_issuer_changeboolean
public_urlstring

GET /api/oidc/callback may change

Return from the provider of the entry oidc

The same return for the entry with the slug oidc (a coupling).

GET /api/oidc/me may change

The sign-in providers of the own account

Every active provider, and whether the own account is linked to it.

GET /api/oidc/providers may change

List the sign-in buttons

The active sign-in providers in their order: slug and the name on the button, nothing else. No sign-in needed - the sign-in and invitation pages ask before anybody is signed in.

GET /api/oidc/{slug}/callback may change

Return from a sign-in provider

The redirect address registered at the provider. Checks the attempt cookie and its single-use state, exchanges the code, verifies the ID token and either starts a session or links the identity to the account that started the linking. Every outcome is a redirect, never a bare API answer.

Fields and shape

Parameters

slugstring path required

POST /api/oidc/{slug}/link may change

Start linking the own account to a provider

Asks for the own password, then returns the provider address to navigate to and sets the attempt cookie. Only in a session, not with a personal access key.

Fields and shape

Parameters

slugstring path required

Request body

FieldType
passwordstring

GET /api/oidc/{slug}/start may change

Go to a sign-in provider

Redirects the browser to the provider (authorization code flow with PKCE, state and nonce in a short-lived attempt cookie). With ?invite=<key> the invitation travels along and is accepted on the way back. Meant to be navigated to; every failure ends on the sign-in page with ?error=<code>.

Fields and shape

Parameters

slugstring path required
invitestring or null query

POST /api/onboarding/forgot-password may change

Request a password reset link

The response is always the same, whether the address exists or not. Otherwise anyone could probe here for who has an account - and on a private installation, that is exactly the list nobody should be able to build.

Fields and shape

Request body

FieldType
emailstring required

Response

FieldType
messagestring required

Response shape

{
  "message": "string"
}

GET /api/onboarding/invitation/{raw} may change

Check an invitation link

Says whether the link is still valid and what it offers, without signing anybody in. Used by the page behind the link to decide between a form and an explanation. If the invitation asks for it and the installation has published house rules, they come along, so the page can show them before the account exists. So do the media servers the invitation grants access to, with their libraries and, where the person brings an account of their own, whether it is linked yet.

Fields and shape

Parameters

rawstring path required

Response

FieldType
emailstring required
roleadmin | approver | user | child required
hausordnungHausordnungSchritt or null
serverlist of ServerFuerPerson

Response shape

{
  "email": "string",
  "role": "admin | approver | user | child",
  "hausordnung": {
    "titel": "string",
    "inhalt": "string",
    "quittierbar": "boolean"
  },
  "server": [
    {
      "provider": "string",
      "label": "string",
      "art": "string",
      "bibliotheken": [
        "string"
      ],
      "zustand": "string",
      "konto_name": "string | null",
      "fehler": "object | null"
    }
  ]
}

POST /api/onboarding/invitation/{raw} may change

Redeem an invitation

Creates the account the way the invited person wants it - username, password, display name. The account does not exist until this call succeeds. The permissions the invitation carries are checked once more against the installation as it is now. Whatever no longer applies is left out, noted on the invitation and reported to the administrators. A decision on the house rules is recorded here as well, never through the signed-in route, because an administrator may still be signed in within the same browser. If the invitation grants access to media servers, accounts on Jellyfin and Emby come first, with the same name and password, while the password is still at hand. If one fails, no Nexview account is created, the invitation stays open and the next attempt continues instead of creating a second account. Shares on Plex follow once the Nexview account exists; a share that fails is noted on the invitation for the administrator to retry. Nothing is ever deleted on a media server.

Fields and shape

Parameters

rawstring path required

Request body

FieldType
usernamestring required
display_namestring or null
passwordstring required
hausordnung_akzeptiertboolean or null

Response

FieldType
usernamestring required
serverlist of ServerFuerPerson

Response shape

{
  "username": "string",
  "server": [
    {
      "provider": "string",
      "label": "string",
      "art": "string",
      "bibliotheken": [
        "string"
      ],
      "zustand": "string",
      "konto_name": "string | null",
      "fehler": "object | null"
    }
  ]
}

GET /api/onboarding/invitation/{raw}/namen may change

Check a username for every account the invitation creates

Answers for Nexview and for each media server where a new account will be created. null means that server did not answer; creating the account checks the name again.

Fields and shape

Parameters

rawstring path required
usernamestring query required

Response

FieldType
nexviewboolean required
serverobject

Response shape

{
  "nexview": "boolean",
  "server": "object"
}

POST /api/onboarding/invitation/{raw}/server/{provider}/poll may change

Check whether linking is finished

Pending until the person confirms at the provider. If that account already belongs to a Nexview account, it stops with a conflict: the administrators are told, the invitation stays open and nothing carries over to the existing account.

Fields and shape

Parameters

rawstring path required
providerstring path required

Request body

FieldType
poll_tokenstring required

Response

FieldType
statusstring required
konto_namestring or null

Response shape

{
  "status": "string",
  "konto_name": "string | null"
}

POST /api/onboarding/invitation/{raw}/server/{provider}/start may change

Start linking the invited person's own media server account

Only for servers where the invitation shares libraries with an account the person already has, which is Plex. Returns a code and a sign-in address; the provider's PIN stays on the server. There is no access check here, because granting access is what the invitation is for.

Fields and shape

Parameters

rawstring path required
providerstring path required

Response

FieldType
poll_tokenstring required
codestring required
auth_urlstring required

Response shape

{
  "poll_token": "string",
  "code": "string",
  "auth_url": "string"
}

GET /api/onboarding/password/{raw} may change

Check a password link

Says whether a reset or first-password link is still valid, so the page can show a form or an explanation instead of failing on submit.

Fields and shape

Parameters

rawstring path required

Response

FieldType
usernamestring required

Response shape

{
  "username": "string"
}

POST /api/onboarding/password/{raw} may change

Set a password

First password or a new one. The address counts as confirmed afterwards - the mail evidently arrived. Every existing session becomes invalid: anyone resetting a password has a reason to assume somebody else was in.

Fields and shape

Parameters

rawstring path required

Request body

FieldType
passwordstring required

PUT /api/onboarding/pending/email may change

Correct an unconfirmed address

The most common reason for a mail that never arrives is a typo. Without this route the installation would be stuck: no confirmed address, no sign-in, and no way to fix the address.

Fields and shape

Request body

FieldType
usernamestring required
passwordstring required
emailstring required

Response

FieldType
sentboolean required
errorstring or null

Response shape

{
  "sent": "boolean",
  "error": "string | null"
}

POST /api/onboarding/pending/resend may change

Send the confirmation mail again, without signing in

The counterpart to the signed-in version, for an account that cannot sign in yet because its address is unconfirmed.

Fields and shape

Request body

FieldType
usernamestring required
passwordstring required

Response

FieldType
sentboolean required
errorstring or null

Response shape

{
  "sent": "boolean",
  "error": "string | null"
}

GET /api/onboarding/username-available may change

Is this username still free

Answers while somebody is still typing. Deliberately open without authentication: whoever is redeeming an invitation is nobody yet. It reveals only whether a name is taken - the same thing the form would reveal on submit.

Fields and shape

Parameters

usernamestring query required

Response

FieldType
availableboolean required

Response shape

{
  "available": "boolean"
}

POST /api/onboarding/verify/{raw} may change

Confirm an e-mail address

Marks the address behind the link as confirmed.

Fields and shape

Parameters

rawstring path required

POST /api/setup/admin may change

Create the first administrator

Only works while the installation is still empty. Afterwards accounts come into being through invitations.

Fields and shape

Request body

FieldType
usernamestring required
passwordstring required
emailstring required
display_namestring or null
languagestring

Response

FieldType
access_tokenstring required
token_typestring
expires_innumber required

Response shape

{
  "access_token": "string",
  "token_type": "string",
  "expires_in": "number"
}

POST /api/setup/seerr/abschliessen may change

Finish the Seerr migration in one go

The one call in this feature that writes, and it writes everything at once or nothing at all: the picked settings areas, the blocklist, the notification channels, the TMDB key, the public address, the owner account and the other accounts. Areas and accounts are picked by name and number; the values themselves are fetched again server-side, so the SMTP password, the Radarr and Sonarr keys and every quota never pass through the browser. Answers with the owner session - the media server is connected with it in the next step. Open only while no account exists; this call creates the first one and closes the door.

Fields and shape

Request body

FieldType
urlstring required
api_keystring required
bereichelist of string
besitzerBesitzerEingabe required
kontenlist of KontoWunsch
tmdb_api_keystring
public_urlstring

Response

FieldType
access_tokenstring required
token_typestring
expires_innumber required
berichtobject required

Response shape

{
  "access_token": "string",
  "token_type": "string",
  "expires_in": "number",
  "bericht": "object"
}

POST /api/setup/seerr/pruefen may change

Check a Seerr installation during first-time setup

Same answer as the admin endpoint, but before there is anyone to sign in as. Open only while no account exists at all; the moment the first one is created this closes for good. Reads only.

Fields and shape

Request body

FieldType
urlstring required
api_keystring required

POST /api/setup/seerr/vorschau may change

Preview a Seerr migration during first-time setup

The decision sheet, built while the installation is still empty. Roles may carry over here, unlike in a running installation: the operator is setting up, and rebuilding years of role assignments by hand is exactly the work this saves. The owner flag never carries over - it belongs to whoever is running the setup. Writes nothing.

Fields and shape

Request body

FieldType
urlstring required
api_keystring required

POST /api/setup/sicherung/einspielen may change

Set up from a backup

Builds the fresh installation from a backup file. Setup is finished afterwards: the accounts come from the backup, and the wizard does not appear again.

POST /api/setup/sicherung/pruefen may change

Inspect a backup file

Reports what a backup contains and whether this version can restore it - without replacing anything. A backup from a newer version is refused, because the database can only be migrated forward.

GET /api/setup/status may change

Is setup still needed

Says whether this installation has been set up yet, and which step it stopped at. Answers without authentication - there is nobody to authenticate as.

Fields and shape

Response

FieldType
needs_setupboolean required
min_password_lengthnumber
mediaserver_loginboolean
mediaserver_providerstring or null
mediaserver_login_wayslist of AnmeldeWeg
password_loginboolean

Response shape

{
  "needs_setup": "boolean",
  "min_password_length": "number",
  "mediaserver_login": "boolean",
  "mediaserver_provider": "string | null",
  "mediaserver_login_ways": [
    {
      "provider": "string",
      "label": "string",
      "kind": "string"
    }
  ],
  "password_login": "boolean"
}

GET /api/users may change

All accounts

Every account with its role, quota and current usage. Administrators only.

Fields and shape

Response

FieldType
idnumber required
usernamestring required
roleadmin | approver | user | child required
display_namestring or null required
emailstring or null required
email_verifiedboolean required
languagestring required
themestring required
is_activeboolean required
is_betreiberboolean
auto_approveboolean required
auto_approve_moviesboolean or null required
auto_approve_seriesboolean or null required
effective_auto_approveboolean required
effective_auto_approve_moviesboolean required
effective_auto_approve_seriesboolean required
can_approveboolean required
quota_movies_limitnumber required
quota_series_limitnumber required
storage_limit_gbnumber
quota_reset_attimestamp (ISO 8601) or null required
hausordnung_gelesen_amtimestamp (ISO 8601) or null
blocked_movie_profileslist of number required
blocked_series_profileslist of number required
fassung_rechtelist of FassungRechtOut
can_request_uhd_moviesboolean required
can_request_uhd_seriesboolean required
auto_approve_uhdboolean required
effective_auto_approve_uhdboolean required
blocked_movie_uhd_profileslist of number required
blocked_series_uhd_profileslist of number required
avatar_urlstring or null required
created_attimestamp (ISO 8601) required
last_login_attimestamp (ISO 8601) or null required
mail_download_completeboolean required
mail_request_pendingboolean required
mail_request_decidedboolean required
mail_feedbackboolean required
mail_ticketboolean required
mail_watchboolean required
mail_user_importedboolean required
mail_mediaserver_reconnectboolean required
mail_storageboolean required
mail_child_wishboolean required
mail_cleanupboolean required
push_download_completeboolean required
push_request_pendingboolean required
push_request_decidedboolean required
push_feedbackboolean required
push_ticketboolean required
push_watchboolean required
push_user_importedboolean required
push_mediaserver_reconnectboolean required
push_storageboolean required
push_child_wishboolean required
watchlist_connectedboolean required
watchlist_token_invalidboolean
mediaserver_providerstring or null required
mediaserver_usernamestring or null required
mediaserver_linkedboolean required
mediaserver_accountslist of VerknuepftesKonto
oidc_linkslist of OidcVerknuepfung
has_passwordboolean required
discover_regionstring or null required
agenumber or null required
rating_regionstring or null required
hide_unratedboolean required
can_manage_childrenboolean
parent_idnumber or null
quota_movies_usednumber required
quota_series_usednumber required

Response shape

[
  {
    "id": "number",
    "username": "string",
    "role": "admin | approver | user | child",
    "display_name": "string | null",
    "email": "string | null",
    "email_verified": "boolean",
    "language": "string",
    "theme": "string",
    "is_active": "boolean",
    "is_betreiber": "boolean",
    "auto_approve": "boolean",
    "auto_approve_movies": "boolean | null",
    "auto_approve_series": "boolean | null",
    "effective_auto_approve": "boolean"
  }
]

GET /api/users/api-schluessel may change

All API tokens in this installation

Who holds which token, when it was made and when it was last used. Never the token itself - an administrator can supervise, not read. Revoking is not offered here: only the owner can switch off their own token.

Fields and shape

Response

FieldType
idnumber required
user_idnumber required
usernamestring required
namestring required
vorschaustring required
nur_lesenboolean required
created_attimestamp (ISO 8601) required
expires_attimestamp (ISO 8601) or null required
last_used_attimestamp (ISO 8601) or null required

Response shape

[
  {
    "id": "number",
    "user_id": "number",
    "username": "string",
    "name": "string",
    "vorschau": "string",
    "nur_lesen": "boolean",
    "created_at": "ISO 8601",
    "expires_at": "ISO 8601 | null",
    "last_used_at": "ISO 8601 | null"
  }
]

GET /api/users/betreiber may change

Who owns this installation

Exactly one account carries the owner flag, and no other administrator can switch it off, delete it, demote it or set its password. user_id: null means nobody carries it - a real state, not an error. aus_umgebung says the owner is pinned by the NEXVIEW_BETREIBER environment variable; while that is set, handing over is refused rather than silently undone on the next restart. Readable by every administrator, not just the owner: whoever meets the greyed-out buttons should be able to find out who they belong to.

Fields and shape

Response

FieldType
user_idnumber or null
usernamestring or null
display_namestring or null
aus_umgebungboolean

Response shape

{
  "user_id": "number | null",
  "username": "string | null",
  "display_name": "string | null",
  "aus_umgebung": "boolean"
}

POST /api/users/betreiber/uebergeben may change

Hand ownership to another administrator

Only the current owner may call this, and there is no way back. The target must be an active administrator - not an ordinary account, not an approver, not a child account, not yourself. Afterwards the previous owner is an ordinary administrator again and is as removable as anyone else. Only the new owner can hand the flag back. The flag grants no rights of its own. It only says what others may not do with that account.

Fields and shape

Request body

FieldType
user_idnumber required

Response

FieldType
user_idnumber or null
usernamestring or null
display_namestring or null
aus_umgebungboolean

Response shape

{
  "user_id": "number | null",
  "username": "string | null",
  "display_name": "string | null",
  "aus_umgebung": "boolean"
}

GET /api/users/invitations may change

Open invitations

Invitations that have neither been redeemed nor expired, plus redeemed ones where something the invitation asked for could not be carried over or a media server is missing. Those stay listed until the administrator dismisses the note.

Fields and shape

Response

FieldType
idnumber required
emailstring required
roleadmin | approver | user | child required
created_attimestamp (ISO 8601) required
expires_attimestamp (ISO 8601) required
eingeloest_amtimestamp (ISO 8601) or null
kontostring or null
entfallenlist of string
serverlist of ServerZiel

Response shape

[
  {
    "id": "number",
    "email": "string",
    "role": "admin | approver | user | child",
    "created_at": "ISO 8601",
    "expires_at": "ISO 8601",
    "eingeloest_am": "ISO 8601 | null",
    "konto": "string | null",
    "entfallen": [
      "string"
    ],
    "server": [
      {
        "provider": "string",
        "label": "string",
        "bibliotheken": [
          "string"
        ],
        "zustand": "string",
        "fehler": "object | null",
        "nachholbar": "boolean"
      }
    ]
  }
]

POST /api/users/invitations may change

Invite somebody

The account comes into being when the link is redeemed, not now. Needs both pieces in place: without a public address the mail contains a dead link, without a mail server it never goes out. Besides role and limits, the invitation carries auto-approval, 4K rights and whether the house rules are shown on redemption. Only what the installation allows at this moment is stored, and redeeming checks the same rules again. It can also grant access to connected media servers, limited to libraries, because that is what all three can do. The chosen libraries are checked against the server before anything is stored.

Fields and shape

Request body

FieldType
roleadmin | approver | user | child
auto_approve_moviesboolean
auto_approve_seriesboolean
fassungenlist of FassungRechtWunsch
can_request_uhd_moviesboolean
can_request_uhd_seriesboolean
auto_approve_uhdboolean
hausordnungboolean
emailstring required
quota_movies_limitnumber
quota_series_limitnumber
storage_limit_gbnumber
serverlist of ServerWunsch

Response

FieldType
idnumber required
emailstring required
roleadmin | approver | user | child required
created_attimestamp (ISO 8601) required
expires_attimestamp (ISO 8601) required
eingeloest_amtimestamp (ISO 8601) or null
kontostring or null
entfallenlist of string
serverlist of ServerZiel
mail_sentboolean required
mail_errorstring or null
manual_linkstring or null

Response shape

{
  "id": "number",
  "email": "string",
  "role": "admin | approver | user | child",
  "created_at": "ISO 8601",
  "expires_at": "ISO 8601",
  "eingeloest_am": "ISO 8601 | null",
  "konto": "string | null",
  "entfallen": [
    "string"
  ],
  "server": [
    {
      "provider": "string",
      "label": "string",
      "bibliotheken": [
        "string"
      ],
      "zustand": "string",
      "fehler": "object | null",
      "nachholbar": "boolean"
    }
  ],
  "mail_sent": "boolean",
  "mail_error": "string | null",
  "manual_link": "string | null"
}

GET /api/users/invitations/server may change

Media servers an invitation can grant access to

Every supported media server, connected or not, with whether an invitation can use it right now and the libraries it can share. The libraries are read from the server itself. Plex libraries carry the plex.tv section id, which is the one sharing needs.

Fields and shape

Response

FieldType
providerstring required
labelstring required
artstring
standRechteStand required
namestring
bibliothekenlist of BibliothekAuswahl
fehlerobject or null

Response shape

[
  {
    "provider": "string",
    "label": "string",
    "art": "string",
    "stand": {
      "frei": "boolean",
      "wirkt": "boolean",
      "grund": "string | null"
    },
    "name": "string",
    "bibliotheken": [
      {
        "kennung": "string",
        "name": "string",
        "art": "string"
      }
    ],
    "fehler": "object | null"
  }
]

DELETE /api/users/invitations/{invitation_id} may change

Withdraw an invitation

The link stops working immediately.

Fields and shape

Parameters

invitation_idnumber path required

POST /api/users/invitations/{invitation_id}/gesehen may change

Dismiss the note on a redeemed invitation

A redeemed invitation stays in the list while something it asked for could not be carried over. This clears that note once the administrator has seen it.

Fields and shape

Parameters

invitation_idnumber path required

POST /api/users/invitations/{invitation_id}/server/{provider}/nachholen may change

Retry a failed share on a media server

After redemption, a share that failed, for example because plex.tv did not answer, stays on the invitation. This tries it again for the account that came out of the invitation. Only shares can be retried: an account on Jellyfin or Emby needs the person's password, which Nexview never keeps.

Fields and shape

Parameters

invitation_idnumber path required
providerstring path required

Response

FieldType
idnumber required
emailstring required
roleadmin | approver | user | child required
created_attimestamp (ISO 8601) required
expires_attimestamp (ISO 8601) required
eingeloest_amtimestamp (ISO 8601) or null
kontostring or null
entfallenlist of string
serverlist of ServerZiel

Response shape

{
  "id": "number",
  "email": "string",
  "role": "admin | approver | user | child",
  "created_at": "ISO 8601",
  "expires_at": "ISO 8601",
  "eingeloest_am": "ISO 8601 | null",
  "konto": "string | null",
  "entfallen": [
    "string"
  ],
  "server": [
    {
      "provider": "string",
      "label": "string",
      "bibliotheken": [
        "string"
      ],
      "zustand": "string",
      "fehler": "object | null",
      "nachholbar": "boolean"
    }
  ]
}

POST /api/users/rechte/bewerten may change

Check which permissions a role can have

Holds the ticked permissions against how the installation is set up and answers per permission: can it be set, will it take effect, and if not, why. The reason is a code the interface translates. The invitation wizard and the account dialog ask on every change, so neither offers more than the rules allow.

Fields and shape

Request body

FieldType
roleadmin | approver | user | child
auto_approve_moviesboolean
auto_approve_seriesboolean
fassungenlist of FassungRechtWunsch
can_request_uhd_moviesboolean
can_request_uhd_seriesboolean
auto_approve_uhdboolean
hausordnungboolean

Response

FieldType
kontingentRechteStand required
auto_approve_moviesRechteStand required
auto_approve_seriesRechteStand required
can_request_uhd_moviesRechteStand required
can_request_uhd_seriesRechteStand required
auto_approve_uhdRechteStand required
hausordnungRechteStand required
fassungenobject
entfallenlist of string required

Response shape

{
  "kontingent": {
    "frei": "boolean",
    "wirkt": "boolean",
    "grund": "string | null"
  },
  "auto_approve_movies": {
    "frei": "boolean",
    "wirkt": "boolean",
    "grund": "string | null"
  },
  "auto_approve_series": {
    "frei": "boolean",
    "wirkt": "boolean",
    "grund": "string | null"
  },
  "can_request_uhd_movies": {
    "frei": "boolean",
    "wirkt": "boolean",
    "grund": "string | null"
  },
  "can_request_uhd_series": {
    "frei": "boolean",
    "wirkt": "boolean",
    "grund": "string | null"
  },
  "auto_approve_uhd": {
    "frei": "boolean",
    "wirkt": "boolean",
    "grund": "string | null"
  },
  "hausordnung": {
    "frei": "boolean",
    "wirkt": "boolean",
    "grund": "string | null"
  },
  "fassungen": "object",
  "entfallen": [
    "string"
  ]
}

DELETE /api/users/{user_id} may change

Delete an account

Approved requests move into the house collection - they stay, just without an owner. Only what is still open gets cancelled. Access on the media servers listed in "serverkonten" is removed before anything else; if that fails on one server, the account and everything it holds stay. Use the preview first to see exactly what will happen.

Fields and shape

Parameters

user_idnumber path required

Request body

FieldType
hauslist of number
loeschenlist of number
staffelnlist of Staffelwahl
offen_behaltenlist of number
serverkontenlist of ServerKontoWahl

PATCH /api/users/{user_id} may change

Change an account

Role, quota, auto-approval, active state and display name. Administrators only.

Fields and shape

Parameters

user_idnumber path required

Request body

FieldType
roleadmin | approver | user | child or null
display_namestring or null
languagestring or null
is_activeboolean or null
auto_approveboolean or null
auto_approve_moviesboolean or null
auto_approve_seriesboolean or null
quota_movies_limitnumber or null
quota_series_limitnumber or null
storage_limit_gbnumber or null
blocked_movie_profileslist of number or null
blocked_series_profileslist of number or null
fassung_rechtelist of FassungRechtWunsch or null
can_request_uhd_moviesboolean or null
can_request_uhd_seriesboolean or null
auto_approve_uhdboolean or null
blocked_movie_uhd_profileslist of number or null
blocked_series_uhd_profileslist of number or null
can_manage_childrenboolean or null

Response

FieldType
idnumber required
usernamestring required
roleadmin | approver | user | child required
display_namestring or null required
emailstring or null required
email_verifiedboolean required
languagestring required
themestring required
is_activeboolean required
is_betreiberboolean
auto_approveboolean required
auto_approve_moviesboolean or null required
auto_approve_seriesboolean or null required
effective_auto_approveboolean required
effective_auto_approve_moviesboolean required
effective_auto_approve_seriesboolean required
can_approveboolean required
quota_movies_limitnumber required
quota_series_limitnumber required
storage_limit_gbnumber
quota_reset_attimestamp (ISO 8601) or null required
hausordnung_gelesen_amtimestamp (ISO 8601) or null
blocked_movie_profileslist of number required
blocked_series_profileslist of number required
fassung_rechtelist of FassungRechtOut
can_request_uhd_moviesboolean required
can_request_uhd_seriesboolean required
auto_approve_uhdboolean required
effective_auto_approve_uhdboolean required
blocked_movie_uhd_profileslist of number required
blocked_series_uhd_profileslist of number required
avatar_urlstring or null required
created_attimestamp (ISO 8601) required
last_login_attimestamp (ISO 8601) or null required
mail_download_completeboolean required
mail_request_pendingboolean required
mail_request_decidedboolean required
mail_feedbackboolean required
mail_ticketboolean required
mail_watchboolean required
mail_user_importedboolean required
mail_mediaserver_reconnectboolean required
mail_storageboolean required
mail_child_wishboolean required
mail_cleanupboolean required
push_download_completeboolean required
push_request_pendingboolean required
push_request_decidedboolean required
push_feedbackboolean required
push_ticketboolean required
push_watchboolean required
push_user_importedboolean required
push_mediaserver_reconnectboolean required
push_storageboolean required
push_child_wishboolean required
watchlist_connectedboolean required
watchlist_token_invalidboolean
mediaserver_providerstring or null required
mediaserver_usernamestring or null required
mediaserver_linkedboolean required
mediaserver_accountslist of VerknuepftesKonto
oidc_linkslist of OidcVerknuepfung
has_passwordboolean required
discover_regionstring or null required
agenumber or null required
rating_regionstring or null required
hide_unratedboolean required
can_manage_childrenboolean
parent_idnumber or null

Response shape

{
  "id": "number",
  "username": "string",
  "role": "admin | approver | user | child",
  "display_name": "string | null",
  "email": "string | null",
  "email_verified": "boolean",
  "language": "string",
  "theme": "string",
  "is_active": "boolean",
  "is_betreiber": "boolean",
  "auto_approve": "boolean",
  "auto_approve_movies": "boolean | null",
  "auto_approve_series": "boolean | null",
  "effective_auto_approve": "boolean"
}

GET /api/users/{user_id}/aufloesung may change

Preview: what deleting would leave behind

What this account would leave behind - without anything happening. The administrator decides with this list in front of them: per item house or delete, per open request keep or cancel, and per account on a media server whether its access goes too ("serverkonten"). Preselected is only what a Nexview invitation created; "grund" says why an entry cannot be removed.

Fields and shape

Parameters

user_idnumber path required

Response

FieldType
postenlist of AufloesungsPosten required
laufendelist of app__routers__users__LaufendeZeile required
offenlist of OffeneZeile required
serverkontenlist of ServerKontoZeile

Response shape

{
  "posten": [
    {
      "id": "number",
      "title": "string",
      "fassung": "string",
      "season": "number | null",
      "media_type": "string",
      "size_bytes": "number"
    }
  ],
  "laufende": [
    {
      "request_id": "number",
      "title": "string",
      "fassung": "string",
      "season": "number | null",
      "dateien": "number",
      "folgen": "number"
    }
  ],
  "offen": [
    {
      "request_id": "number",
      "title": "string",
      "fassung": "string",
      "season": "number | null"
    }
  ],
  "serverkonten": [
    {
      "provider": "string",
      "label": "string",
      "konto": "string",
      "name": "string",
      "art": "string",
      "aus_einladung": "boolean",
      "vorausgewaehlt": "boolean",
      "grund": "string | null"
    }
  ]
}

POST /api/users/{user_id}/password may change

Set an account's password

An administrator sets a new password directly, for the case where mail is not working and the reset link cannot arrive.

Fields and shape

Parameters

user_idnumber path required

Request body

FieldType
passwordstring required

POST /api/users/{user_id}/quota/reset may change

Reset the request count

Sets usage in the current period back to zero. The requests themselves stay - counting simply starts again from now. At the next period change the calendar takes over as usual.

Fields and shape

Parameters

user_idnumber path required

Response

FieldType
idnumber required
usernamestring required
roleadmin | approver | user | child required
display_namestring or null required
emailstring or null required
email_verifiedboolean required
languagestring required
themestring required
is_activeboolean required
is_betreiberboolean
auto_approveboolean required
auto_approve_moviesboolean or null required
auto_approve_seriesboolean or null required
effective_auto_approveboolean required
effective_auto_approve_moviesboolean required
effective_auto_approve_seriesboolean required
can_approveboolean required
quota_movies_limitnumber required
quota_series_limitnumber required
storage_limit_gbnumber
quota_reset_attimestamp (ISO 8601) or null required
hausordnung_gelesen_amtimestamp (ISO 8601) or null
blocked_movie_profileslist of number required
blocked_series_profileslist of number required
fassung_rechtelist of FassungRechtOut
can_request_uhd_moviesboolean required
can_request_uhd_seriesboolean required
auto_approve_uhdboolean required
effective_auto_approve_uhdboolean required
blocked_movie_uhd_profileslist of number required
blocked_series_uhd_profileslist of number required
avatar_urlstring or null required
created_attimestamp (ISO 8601) required
last_login_attimestamp (ISO 8601) or null required
mail_download_completeboolean required
mail_request_pendingboolean required
mail_request_decidedboolean required
mail_feedbackboolean required
mail_ticketboolean required
mail_watchboolean required
mail_user_importedboolean required
mail_mediaserver_reconnectboolean required
mail_storageboolean required
mail_child_wishboolean required
mail_cleanupboolean required
push_download_completeboolean required
push_request_pendingboolean required
push_request_decidedboolean required
push_feedbackboolean required
push_ticketboolean required
push_watchboolean required
push_user_importedboolean required
push_mediaserver_reconnectboolean required
push_storageboolean required
push_child_wishboolean required
watchlist_connectedboolean required
watchlist_token_invalidboolean
mediaserver_providerstring or null required
mediaserver_usernamestring or null required
mediaserver_linkedboolean required
mediaserver_accountslist of VerknuepftesKonto
oidc_linkslist of OidcVerknuepfung
has_passwordboolean required
discover_regionstring or null required
agenumber or null required
rating_regionstring or null required
hide_unratedboolean required
can_manage_childrenboolean
parent_idnumber or null
quota_movies_usednumber required
quota_series_usednumber required

Response shape

{
  "id": "number",
  "username": "string",
  "role": "admin | approver | user | child",
  "display_name": "string | null",
  "email": "string | null",
  "email_verified": "boolean",
  "language": "string",
  "theme": "string",
  "is_active": "boolean",
  "is_betreiber": "boolean",
  "auto_approve": "boolean",
  "auto_approve_movies": "boolean | null",
  "auto_approve_series": "boolean | null",
  "effective_auto_approve": "boolean"
}

POST /api/users/{user_id}/storage/reset may change

Move an account's storage to the house

The counterpart to resetting the request count, and the way out of a ghost item: something requested through Nexview that no longer exists in Radarr or Sonarr keeps counting against its owner forever otherwise.

Fields and shape

Parameters

user_idnumber path required

Response

FieldType
idnumber required
usernamestring required
roleadmin | approver | user | child required
display_namestring or null required
emailstring or null required
email_verifiedboolean required
languagestring required
themestring required
is_activeboolean required
is_betreiberboolean
auto_approveboolean required
auto_approve_moviesboolean or null required
auto_approve_seriesboolean or null required
effective_auto_approveboolean required
effective_auto_approve_moviesboolean required
effective_auto_approve_seriesboolean required
can_approveboolean required
quota_movies_limitnumber required
quota_series_limitnumber required
storage_limit_gbnumber
quota_reset_attimestamp (ISO 8601) or null required
hausordnung_gelesen_amtimestamp (ISO 8601) or null
blocked_movie_profileslist of number required
blocked_series_profileslist of number required
fassung_rechtelist of FassungRechtOut
can_request_uhd_moviesboolean required
can_request_uhd_seriesboolean required
auto_approve_uhdboolean required
effective_auto_approve_uhdboolean required
blocked_movie_uhd_profileslist of number required
blocked_series_uhd_profileslist of number required
avatar_urlstring or null required
created_attimestamp (ISO 8601) required
last_login_attimestamp (ISO 8601) or null required
mail_download_completeboolean required
mail_request_pendingboolean required
mail_request_decidedboolean required
mail_feedbackboolean required
mail_ticketboolean required
mail_watchboolean required
mail_user_importedboolean required
mail_mediaserver_reconnectboolean required
mail_storageboolean required
mail_child_wishboolean required
mail_cleanupboolean required
push_download_completeboolean required
push_request_pendingboolean required
push_request_decidedboolean required
push_feedbackboolean required
push_ticketboolean required
push_watchboolean required
push_user_importedboolean required
push_mediaserver_reconnectboolean required
push_storageboolean required
push_child_wishboolean required
watchlist_connectedboolean required
watchlist_token_invalidboolean
mediaserver_providerstring or null required
mediaserver_usernamestring or null required
mediaserver_linkedboolean required
mediaserver_accountslist of VerknuepftesKonto
oidc_linkslist of OidcVerknuepfung
has_passwordboolean required
discover_regionstring or null required
agenumber or null required
rating_regionstring or null required
hide_unratedboolean required
can_manage_childrenboolean
parent_idnumber or null
quota_movies_usednumber required
quota_series_usednumber required

Response shape

{
  "id": "number",
  "username": "string",
  "role": "admin | approver | user | child",
  "display_name": "string | null",
  "email": "string | null",
  "email_verified": "boolean",
  "language": "string",
  "theme": "string",
  "is_active": "boolean",
  "is_betreiber": "boolean",
  "auto_approve": "boolean",
  "auto_approve_movies": "boolean | null",
  "auto_approve_series": "boolean | null",
  "effective_auto_approve": "boolean"
}