REST API
Drive every Hugin tool over HTTP — the same control surface the GUI and the MCP agent use, described by /openapi.json.
Everything in Hugin's window goes over one local HTTP API, and so does the MCP
agent. It's the same control surface — more than 1,000 routes under /api/ — so
anything you can click, you can script. The API listens on 127.0.0.1:8081 by
default (the proxy itself is a separate listener on 8080).
Talk to it
Start a headless instance, or just hit the port the desktop app already opened:
hugin --headless start --api-port 8081
# List captured flows
curl http://127.0.0.1:8081/api/flows
# Read proxy status
curl http://127.0.0.1:8081/api/proxy/status
See the command line for the rest of the headless flags.
What you can drive
List, search, tag, and delete captured traffic; set what's in and out of scope.
Replay and tamper a single request, or fuzz it across payload sets.
Start scans, poll status, pull findings.
Hold a live request, edit it, then forward or drop it.
Drive the Chrome-fingerprinted browser — navigate, screenshot, harvest cookies.
Mint out-of-band (OOB) payloads and read the callbacks they catch.
Chain steps into an automated run, or share a live session.
The spec is machine-readable
Hugin serves its own OpenAPI spec — point your HTTP client, code generator, or an agent straight at it instead of guessing routes:
curl http://127.0.0.1:8081/openapi.json
The same document is at /api/schema. It's served without a token by default so
Swagger UI and SDK generators can read the route shapes.
Auth and shared instances
On a local bind the API answers with no token. To run an instance your team — or your CI — reaches over the network, mint a bearer token and send it on every call:
hugin token create # prints an hgn_... token once
curl -H "Authorization: Bearer hgn_..." http://HOST:8081/api/flows
hugin serve runs that shared headless instance with token auth on. To let an AI
agent drive the same surface, see MCP.
The control API is unauthenticated on a local bind, and role enforcement is
permissive by default: with no X-Hugin-Role header a caller gets the admin set —
full read, write, scan, and config. hugin serve binds 0.0.0.0. Anyone who
reaches the control port can read your captured traffic, send requests as you, and
rewrite scope. Keep it on 127.0.0.1, and for any shared instance turn on token
auth and set HUGIN_REST_RBAC_STRICT=1 so an unidentified caller drops to
read-only. Never expose the control port to the open internet.