docs

REST API

Drive every Hugin tool over HTTP — the same control surface the GUI and the MCP agent use, described by /openapi.json.

Everything in Hugin's window goes over one local HTTP API, and so does the MCP agent. It's the same control surface — more than 1,000 routes under /api/ — so anything you can click, you can script. The API listens on 127.0.0.1:8081 by default (the proxy itself is a separate listener on 8080).

Talk to it

Start a headless instance, or just hit the port the desktop app already opened:

hugin --headless start --api-port 8081

# List captured flows
curl http://127.0.0.1:8081/api/flows

# Read proxy status
curl http://127.0.0.1:8081/api/proxy/status

See the command line for the rest of the headless flags.

What you can drive

Flows and scope

List, search, tag, and delete captured traffic; set what's in and out of scope.

Repeater and Intruder

Replay and tamper a single request, or fuzz it across payload sets.

Scanner

Start scans, poll status, pull findings.

Intercept

Hold a live request, edit it, then forward or drop it.

Browser

Drive the Chrome-fingerprinted browser — navigate, screenshot, harvest cookies.

Oastify

Mint out-of-band (OOB) payloads and read the callbacks they catch.

Workflows and collaboration

Chain steps into an automated run, or share a live session.

The spec is machine-readable

Hugin serves its own OpenAPI spec — point your HTTP client, code generator, or an agent straight at it instead of guessing routes:

curl http://127.0.0.1:8081/openapi.json

The same document is at /api/schema. It's served without a token by default so Swagger UI and SDK generators can read the route shapes.

Auth and shared instances

On a local bind the API answers with no token. To run an instance your team — or your CI — reaches over the network, mint a bearer token and send it on every call:

hugin token create          # prints an hgn_... token once
curl -H "Authorization: Bearer hgn_..." http://HOST:8081/api/flows

hugin serve runs that shared headless instance with token auth on. To let an AI agent drive the same surface, see MCP.

The control API is unauthenticated on a local bind, and role enforcement is permissive by default: with no X-Hugin-Role header a caller gets the admin set — full read, write, scan, and config. hugin serve binds 0.0.0.0. Anyone who reaches the control port can read your captured traffic, send requests as you, and rewrite scope. Keep it on 127.0.0.1, and for any shared instance turn on token auth and set HUGIN_REST_RBAC_STRICT=1 so an unidentified caller drops to read-only. Never expose the control port to the open internet.

Last updated 2026-06-17.