The API
FileRun 2026.3, API changes
This page lists the API endpoints added and changed since FileRun 2026.2.1.
For the changes introduced with FileRun 2026.1.0, see the migration guide.
Version 2026.3.0
New scope: comments
The file comments endpoints require the new comments scope. Request it together with the other scopes when obtaining the access token.
New endpoints
| Endpoint | Documentation |
|---|---|
/api.php/Drive/files/lock |
Locking files |
/api.php/Drive/files/unlock |
Locking files |
/api.php/Drive/files/comments/list |
File comments |
/api.php/Drive/files/comments/add |
File comments |
/api.php/Drive/files/comments/delete |
File comments |
/api.php/Drive/files/tags/list |
Listing tags |
/api.php/Drive/files/tags/remove |
Removing tags |
/api.php/Drive/files/trash/item/restore |
Managing the trash |
/api.php/Drive/files/trash/item/delete |
Managing the trash |
/api.php/Drive/files/trash/empty |
Managing the trash |
/api.php/Core/!admin/users/deactivate |
Deactivate FileRun user accounts |
/api.php/Core/!admin/groups/search |
Managing groups |
/api.php/Core/!admin/groups/info |
Managing groups |
/api.php/Core/!admin/groups/add |
Managing groups |
/api.php/Core/!admin/groups/edit |
Managing groups |
/api.php/Core/!admin/groups/delete |
Managing groups |
/api.php/Core/!admin/groups/add_users |
Managing groups |
/api.php/Core/!admin/groups/remove_user |
Managing groups |
/api.php/Core/!admin/roles/info |
Managing roles |
/api.php/Core/!admin/roles/add |
Managing roles |
/api.php/Core/!admin/roles/edit |
Managing roles |
/api.php/Core/!admin/roles/delete |
Managing roles |
Changed endpoints
/api.php/Drive/files/delete
- When the item is moved to the trash, the response carries
trash_path, the path by which the item can be restored or permanently deleted.
/api.php/Drive/files/metadata/fields
- Requires the
metadatascope and the account permission to access metadata. Any access token was accepted before. See Listing metadata fields.
/api.php/Core/account/info
- The
2faproperty is no longer returned.
/api.php/Core/!admin/users/add and /api.php/Core/!admin/users/edit
data[two_step_enabled]is renameddata[require_2fa].perms[change_pass]is renamedperms[change_auth].- A role which grants administrative permissions can be assigned only by the superuser.
- Every group named in
groupsmust be one the administrator is allowed to manage. Otherwise the request is refused before the account is created. - The edit endpoint answers with the
msgarray, like the other endpoints. - An edit request which does not send
data[userIsActive]leaves the activation state of the account as it is. Before, such a request deactivated the account. data[two_step_reset](set to 1) removes the second authentication factor of the account.- Changing the password revokes the sessions, the OAuth2 tokens and the app passwords of the account.
/api.php/Core/!admin/users/info
- The response no longer carries the password hash and the two-step authentication secrets.
- The response carries
special_type, which isguestfor a guest account. See Get FileRun user account information for the list of fields.
/api.php/Core/!admin/users/edit_groups
- The administrator must be allowed to manage the account. Otherwise the request is refused. See Set the groups of a FileRun user account.
/api.php/Core/!admin/users/!super/app_password
- Takes an optional
namefor the app password. - Refuses to create an app password for the caller's own account, for guest accounts and for administrator accounts.
- The
usernamereturned is the public id of the account.
/api.php/Core/users/search
- Only person accounts are returned: regular accounts and guest accounts. Internal accounts, such as the System account, are left out.
Removed: /api.php/Core/account/password
- The endpoint for changing the password of the account is removed.
Version 2026.3.1
New endpoint: /api.php/Drive/files/copy
- Copies a file or a folder. See Copying files or folders.
/api.php/Drive/files/move
- Takes the
overwriteparameter. When set to 1, a move onto an existing file replaces it. See Moving files or folders.
/api.php/Drive/files/extract and /api.php/Drive/files/zip
- Extracting and zipping no longer require the permission to make changes. Being allowed to download the source and to upload into the target folder is enough.
- Extracting over a file which already exists requires that the account is allowed to delete that file and to upload into its folder. An account holding the
editorshare role on a folder, without the permission to rename, move and delete, cannot extract over existing files any more.
Permission names
The permission "User can make changes to files and folders" (perms[changes] on the user and role endpoints, readonly in the stored records) is split into five permissions:
| Name | Meaning |
|---|---|
edit_files |
Edit existing files, including managing their previous versions |
rename_move_delete |
Rename, move and delete files and folders, including the trash and writing over existing files |
collections |
Create and manage collections and photo albums |
starring |
Star files and folders |
write_metadata |
Change tags, ratings and other metadata |
- The user endpoints (
!admin/users/add,!admin/users/edit) and the role endpoints (!admin/roles/add,!admin/roles/edit) take the five names.perms[changes]is still accepted, as an alias ofrename_move_delete. !admin/roles/infoand!admin/users/infohand out the five names.readonlyandchangesare still handed out as aliases ofrename_move_delete.account/infolists the five names underpermissions.readOnlyis still returned, as the negation ofrename_move_delete.- Clients are recommended to move to the new names. An edit through the user endpoints which still sends only
changesstores the other four permissions of the edited account as 0, because those endpoints rebuild the whole permissions record from the request. The role endpoints write only what the request names, so they are not affected.