Desktop launches a bundled local server automatically. Use forge serve for headless, remote, or development scenarios.
Network options
- Hostname defaults to loopback.
- The listener prefers port 4096 when available.
- mDNS discovery is opt-in.
- CORS origins must be configured explicitly.
- Basic authentication is enabled when server credentials are provided.
Do not expose an unauthenticated TurenOS server to an untrusted network. The API can access projects, sessions, providers, tools, and local execution authority.
Health and authentication
The health endpoint returns { "healthy": true } when the server is ready. Other endpoints use the same configured Basic Auth credentials.
API groups
The typed HTTP API includes global events and health, projects and workspaces, files and search, sessions and messages, prompts and durable input, permissions, providers/models, MCP, Extensions, automations, memory, terminal/PTY, and review operations. Automation CRUD and run operations (create, list, get, edit, pause, resume, delete, run-now, run list/get/cancel) are exposed on HTTP; event firing (fireEvent) is core-only, driven by the local scheduler watching the filesystem and session events, and is not on the HTTP API.
SDKs
Generated JavaScript clients are versioned with the server protocol. sdk-next composes client, core, and server services for embedded use. Prefer the generated client over handwritten URLs so path, schema, and error contracts stay aligned.
For local attachment: