curl --request POST \
--url http://localhost:3000/api/auth/developer \
--header 'Content-Type: application/json' \
--cookie __Host-argus-session= \
--data '
{
"password": "<developer access password>"
}
'import requests
url = "http://localhost:3000/api/auth/developer"
payload = { "password": "<developer access password>" }
headers = {
"cookie": "__Host-argus-session=",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {cookie: '__Host-argus-session=', 'Content-Type': 'application/json'},
body: JSON.stringify({password: '<developer access password>'})
};
fetch('http://localhost:3000/api/auth/developer', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_PORT => "3000",
CURLOPT_URL => "http://localhost:3000/api/auth/developer",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'password' => '<developer access password>'
]),
CURLOPT_COOKIE => "__Host-argus-session=",
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "http://localhost:3000/api/auth/developer"
payload := strings.NewReader("{\n \"password\": \"<developer access password>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("cookie", "__Host-argus-session=")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("http://localhost:3000/api/auth/developer")
.header("cookie", "__Host-argus-session=")
.header("Content-Type", "application/json")
.body("{\n \"password\": \"<developer access password>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("http://localhost:3000/api/auth/developer")
http = Net::HTTP.new(url.host, url.port)
request = Net::HTTP::Post.new(url)
request["cookie"] = '__Host-argus-session='
request["Content-Type"] = 'application/json'
request.body = "{\n \"password\": \"<developer access password>\"\n}"
response = http.request(request)
puts response.read_body{
"data": {
"developerAccess": true
}
}{
"error": {
"code": "AUTHENTICATION_FAILED",
"message": "Authentication failed."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "USER_REQUIRED",
"message": "A signed-in user is required."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "RATE_LIMITED",
"message": "Too many requests."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "INTERNAL_ERROR",
"message": "The request could not be completed."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}Enable Developer Access
Permission: None beyond being signed in.
Access: Browser session only.
Temporary, internal. Grants the current session every permission in the catalogue until the session ends or access is revoked. It changes no role, staff or permission record, and other sessions are unaffected. Disabled entirely unless the server has ARGUS_DEVELOPER_PASSWORD set.
Business rules still apply: Developer Access does not create a staff profile.
Limited to five attempts per account per 15 minutes. A malformed body is answered the same way as a wrong password.
curl --request POST \
--url http://localhost:3000/api/auth/developer \
--header 'Content-Type: application/json' \
--cookie __Host-argus-session= \
--data '
{
"password": "<developer access password>"
}
'import requests
url = "http://localhost:3000/api/auth/developer"
payload = { "password": "<developer access password>" }
headers = {
"cookie": "__Host-argus-session=",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {cookie: '__Host-argus-session=', 'Content-Type': 'application/json'},
body: JSON.stringify({password: '<developer access password>'})
};
fetch('http://localhost:3000/api/auth/developer', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_PORT => "3000",
CURLOPT_URL => "http://localhost:3000/api/auth/developer",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'password' => '<developer access password>'
]),
CURLOPT_COOKIE => "__Host-argus-session=",
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "http://localhost:3000/api/auth/developer"
payload := strings.NewReader("{\n \"password\": \"<developer access password>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("cookie", "__Host-argus-session=")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("http://localhost:3000/api/auth/developer")
.header("cookie", "__Host-argus-session=")
.header("Content-Type", "application/json")
.body("{\n \"password\": \"<developer access password>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("http://localhost:3000/api/auth/developer")
http = Net::HTTP.new(url.host, url.port)
request = Net::HTTP::Post.new(url)
request["cookie"] = '__Host-argus-session='
request["Content-Type"] = 'application/json'
request.body = "{\n \"password\": \"<developer access password>\"\n}"
response = http.request(request)
puts response.read_body{
"data": {
"developerAccess": true
}
}{
"error": {
"code": "AUTHENTICATION_FAILED",
"message": "Authentication failed."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "USER_REQUIRED",
"message": "A signed-in user is required."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "RATE_LIMITED",
"message": "Too many requests."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "INTERNAL_ERROR",
"message": "The request could not be completed."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}Authorizations
The opaque session cookie set by Discord sign-in. Named argus-session outside production. HttpOnly, so scripts cannot read it; same-origin requests send it automatically. Requests other than GET must also carry an Origin header equal to the application's own origin.
Body
1 - 4096Response
Success.
Show child attributes
Show child attributes