Developers & API
The HiddenIO API is a read-only JSON interface over the public index. The full, always-current reference — including request/response examples for every endpoint — lives at the interactive docs: [/api-docs](https://hiddenio.com/api-docs) (served from the API origin). The summary below is a convenience copy.
Endpoints
All endpoints are prefixed with /api/v1. Highlights:
GET /configs— query the index (filters:q,protocol,country,freshness,
transport, security, source_id, min_sources, sort, limit, cursor).
GET /configs/{id}— one record with per-source observations.GET /protocols,GET /countries,GET /sources— dimension listings with counts.GET /stats/*— overview, protocol/country/freshness distributions, 30-day timeseries.GET /trending,GET /status,GET /guides— page-support data.- Data feeds live outside
/api:GET /sub/{spec}?format=raw|base64|clash|sing-box|jsonwith ETag
caching, plus prebuilt /downloads/{key} artifacts.
Responses use cursor pagination: pass the opaque next_cursor back as cursor to continue.
Authentication
Public GET endpoints work without an account (per-IP limits). For stable programmatic access, create an API key under Account → API keys and send it as a header:
X-API-Key: hio_…Keys are shown in full exactly once, are stored hashed, carry a daily quota, and can be revoked at any time.
The HiddenIO API is a read-only JSON interface over the public index. The full, always-current reference — including request/response examples for every endpoint — lives at the interactive docs: /api-docs (served from the API origin).
Rate limits
Conventions
- Timestamps are ISO-8601 UTC; freshness values are fresh | recent | aging | stale | archived.
- Errors are JSON: {"detail": "…"} with proper status codes.
- Create a key on the API keys page and send
X-API-Key: hio_…on every request.