The lok.computer public REST API exposes discovery and health responses plus the read-oriented data services used by the browser desktop.
Start with GET https://lok.computer/api/status. It is a credential-free, side-effect-free request suitable for connectivity checks and integration tests. Then read https://lok.computer/openapi.json for the authoritative OpenAPI 3.1 operation definitions, parameters, request bodies, response schemas, and operation identifiers. JSON is returned as application/json. Unknown API routes return HTTP 404 rather than a successful placeholder.
No client API key is currently issued or required for the documented public endpoints. Server-side credentials used to reach upstream services are never provided to callers. The API has no separate write sandbox because the documented data operations are read-only; use /api/status as the safe test endpoint. The AI operations are the exception to the read-only model: AI chat forwards supplied messages to a configured model, and Ask AI (planJevQuestions, askJev) sends a request and optional content to a planner model and to TypeSafe's Jev; neither should receive secrets or personal data.
This is a public personal-project API with no published service-level agreement. Clients should use modest request rates, cache successful reads, honor HTTP errors, and apply exponential backoff to transient failures. Some operations depend on upstream services and can fail when an upstream token expires, a provider is unavailable, or public content changes. A 200 response from /api/status confirms the lok.computer Worker is reachable; it does not guarantee every upstream provider is healthy.
There are currently no webhooks, OAuth client registration, MCP server, write API, or separately published official CLI. Agents can call the REST endpoints directly with any standards-compliant HTTP client. Feature requests and source-level questions belong in the GitHub repository; private and security-sensitive reports should use the contact address.