Pi-hole Auth API

Session authentication.

Operations 2

POST /api/auth Create a session #
DELETE /api/auth Log out and invalidate the current session #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/pi-hole-auth-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

pi-hole-auth-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Pi-hole REST Auth API
  description: 'REST API exposed by the pihole-FTL binary (v6+) for managing DNS

    blocklists, allowlists, groups, clients, configuration, and query logs

    on a Pi-hole instance. Most endpoints require an authenticated session

    (SID); obtain one via POST /api/auth and send it back on subsequent

    requests as the `X-FTL-SID` header, the `sid` query parameter, or in the

    request body. Each Pi-hole serves its own OpenAPI/Swagger documentation

    at /api/docs that exactly matches its installed version.


    Only a representative subset of the Pi-hole API surface (auth, groups,

    DNS blocking, info/version) is modeled here. See the documentation

    linked under externalDocs for the full catalog.

    '
  version: 6.0.0
  contact:
    name: Pi-hole documentation
    url: https://docs.pi-hole.net/api/
  license:
    name: EUPL-1.2
    url: https://opensource.org/license/eupl-1-2/
servers:
- url: http://{piHoleHost}
  description: Local Pi-hole instance.
  variables:
    piHoleHost:
      default: pi.hole
      description: Hostname or IP of the Pi-hole server.
security:
- sidHeader: []
tags:
- name: Auth
  description: Session authentication.
paths:
  /api/auth:
    post:
      tags:
      - Auth
      summary: Create a session
      description: 'Authenticate against Pi-hole using the admin password (or an

        application password) and receive a session identifier (SID) plus

        CSRF token. The SID is then sent on subsequent requests via the

        `X-FTL-SID` header, a `sid` query parameter, the request body, or

        a `sid` cookie (cookie requires `X-FTL-CSRF`).

        '
      operationId: createSession
      security: []
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                password:
                  type: string
                  description: Pi-hole admin or application password.
      responses:
        '200':
          description: Session created.
          content:
            application/json:
              schema:
                type: object
                properties:
                  session:
                    type: object
                    properties:
                      valid:
                        type: boolean
                      sid:
                        type: string
                      csrf:
                        type: string
                      validity:
                        type: integer
        '401':
          description: Authentication failed.
    delete:
      tags:
      - Auth
      summary: Log out and invalidate the current session
      operationId: deleteSession
      responses:
        '204':
          description: Session invalidated.
components:
  securitySchemes:
    sidHeader:
      type: apiKey
      in: header
      name: X-FTL-SID
      description: Session identifier returned by POST /api/auth.
externalDocs:
  description: Pi-hole API documentation
  url: https://docs.pi-hole.net/api/