* fix(sports): share the ESPN rejected-range memo with the background service BackgroundDataService always sent a season range first and, on a 400, fell back to chunks without recording the rejection, so every background season fetch spent a doomed request and live scoreboards learned nothing from it (or it from them). The worker now consults and sets the same 6-hour memo fetch_espn_scoreboard() uses: a known rejection goes straight to month/day chunks, and if every chunk fails the range is asked once for a real error without re-spending the chunks. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(web): keep plugin asset and action routes inside their directories POST /plugins/assets/upload, GET /plugins/assets/list and POST /plugins/assets/delete joined the request's plugin_id onto assets/plugins unchecked, so '../../config' created, wrote, listed and deleted outside it. #561 guarded only the route that serves the files. All three now go through path_safety.resolve_under and answer 400 for anything but a plain name, and delete only unlinks a metadata path that resolves into that plugin's uploads directory. PluginManager.get_plugin_directory refuses ids that are not one plain path segment, so /plugins/action (which runs a manifest script from the returned directory) and every other caller get the guard; the action route also rejects such ids up front, covering its no-manager fallback. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(web): report a no-op plugin update as already up to date update_plugin() returns True both for a real update and for "nothing to do" (a ZIP-installed monorepo plugin already at the registry version, a bundled plugin). With no git commit to compare, POST /plugins/update called every such success "updated successfully", so Check & Update All counted most official plugins as updated on every run. The route now reads what changed off the plugin itself (commit, else manifest version, else last_updated) and returns data.update_status (updated / up_to_date / local_only). The update-all toast is summarised by PluginInstallManager.summarizeUpdateResults from that status, falling back to the message for older servers. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(sports): scoreboard scroll speed no longer follows target_fps sports_scroll computed the crisp speed ladder against the global target_fps whenever limit_refresh_rate_hz was the 100 Hz default. Since frame-locked presentation (#545) the helper steps a fixed number of whole pixels per presented frame and the panel presents at its real refresh, so the General tab's "Scroll Frame Rate" became a speed multiplier: 60 ran a 50 px/s scoreboard at 100 px/s, 200 ran it at 25 px/s. The ladder now uses the display manager's refresh_hz, then display.hardware.limit_refresh_rate_hz, then the default. target_fps is not consulted. Docstrings now say scroll_delay is ignored for pacing (no behaviour change there) and describe the fixed-step model. Tests: replace the tests that pinned target_fps as the ladder refresh and described time-based stepping; assert speed independence from target_fps (unit and end-to-end presented px/s against the real helper), that the fixed per-frame step is applied, and that scroll_delay does not change speed. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(web): escape registry and upload values in plugin manager inline handlers The store, saved-repository and custom-registry buttons built onclick='...(${JSON.stringify(id)})...'. JSON.stringify leaves ' alone, so a custom registry entry whose id contained ' closed the attribute and added its own handler. One helper, jsStringAttr(), now HTML-escapes the JSON literal for every one of those handlers, and the store View button opens only http(s) repo links. The live window.updateImageList (plugins_manager.js loads last, so its copy wins over the file-upload widget's) wrote the uploaded file's original name, path and ids into markup raw; they are escaped now. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(changelog): note plugin asset, action and inline handler guards Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(update): let the root pip wrapper install web_interface/requirements.txt Update Code, the automatic update's health check and Install Base Requirements install web_interface/requirements.txt through safe_pip_install.sh, which only allowed the root requirements.txt. The first commit changing that file would fail its dependency install, and the automatic updater rolls back any update whose dependencies did not install -- on every device, for every newer commit. The wrapper now lists both core requirement files. Only their folders are resolved, so a requirements.txt symlinked out of the project is compared by its target and refused (previously the root file's own symlink target was what got allowed). The updater's file list is a named constant, and a test runs the real wrapper (pip stubbed) on every file Update Code and the rollback install. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(web): do not retry plugin requests that got an HTTP answer PluginAPI.request wrapped everything that was not a structured error as NETWORK_ERROR: a proxy's 502 HTML page (response.json() throws) and a JSON error without error_code included. Check & Update All retries NETWORK_ERROR, so those updates were re-sent five more times with backoff, contrary to the #587 contract that an HTTP error response is the server's answer. NETWORK_ERROR now means only that fetch() rejected. Any HTTP response without an error_code, or with a body that is not JSON, is API_ERROR with the HTTP status attached. Tested against the shipped api_client.js. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(scroll): restart the stats window when an idle gap is dropped by size #582 dropped an idle gap from the frame stats two ways: the reset_scroll() sentinel, which also restarts the 5s window timer, and a size guard for scrollers that never call reset_scroll(), which did not. On that path the first real frame after the gap found the boundary overdue and logged a stats line for a one-frame window. Both paths now share one seeding helper. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(update): leave plugins alone when update_core's own rollback fails update_core returns rollback_failed directly when a partial pull or an update whose health check never started cannot be rolled back. run() only held plugins back for 'verifying', so those devices still got new plugin versions and a display restart on top of a core in an unknown state -- the opposite of what the health-check path does, and of the 3.4.0 changelog (plugins are left alone if the rollback fails). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(api): make the REST reference match the api_v3 package Every documented request body, query parameter and response shape was re-checked against the handlers in web_interface/blueprints/api_v3/. Fixes calls that failed as documented (repo_url, action_id/params, files/image_id, font_file+font_family, ?font=, cache key, auto_enable_ap_mode, plugin limit keys), removes the font-override endpoints dropped in #566, corrects response shapes (plugins/config, plugins/schema, health, metrics, operation history, github-status, fonts/catalog, cache/list, logs, wifi, on-demand, SSE streams), and adds the 26 routes it omitted (backup, system auto-update/git, wifi radio, starlark editor, MQTT bridge, status endpoints, skins). Documents the merge semantics of partial JSON saves to /config/main and /plugins/config and the dim-schedule POST accepting GET's days shape, which land in the same change set. Replaces app.py line numbers and the removed api_v3.py path with file and function names. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(web): remove the General-tab plugin system toggles that did nothing plugin_system.auto_discover, auto_load_enabled and development_mode had General-tab toggles whose help tips promised dormant plugins and verbose logging, but nothing reads them: every enabled plugin is discovered and loaded regardless. Remove the three toggles. The keys stay tolerated in stored configs. The save handler now stores a flag only when a client sends it; treating a missing key as an unchecked box would otherwise rewrite all three to false on every General-tab save, which still posts plugins_directory. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * refactor(scroll): remove dead code left by #523/#570 - Drop the optional scipy.ndimage import and HAS_SCIPY; nothing read them since the numpy blend replaced the scipy path. - Drop ScrollHelper._last_integer_position and frame_time_target, which were written but never read. - Keep target_fps and set_target_fps() but document them as informational: nothing paces off them, yet ledmatrix-elections' test_scroll_pacing.py reads helper.target_fps back and third-party plugins may call the setter. - Fix stale comments: fixed_pixels_per_frame's "use scroll_delay to throttle", set_sub_pixel_scrolling's "default: True", and set_frame_based_scrolling's claim that it steps. The plugins monorepo was grepped for every removed name; none is used. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(fonts): point plugins at plugin_manager.font_manager; drop removed overrides UI FONT_MANAGER.md told plugins to read display_manager.font_manager, which does not exist, so a plugin following it failed to load with AttributeError. The shared FontManager lives on the PluginManager and BasePlugin._get_font_manager() returns it (with a fallback for harnesses). Also removes the Fonts-tab override workflow and element-override panels that #566 deleted, from FONT_MANAGER.md and WEB_INTERFACE_GUIDE.md. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(store): search via /plugins/store/list?query=; send Content-Type on registry curls /plugins/store/search does not exist (404) and the list endpoint reads query, not q. The registry guide's curl examples omitted the JSON Content-Type, so the handlers saw an empty body and answered 400. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(config): use the shared core-key list in the last three private copies StartupValidator warned "Plugin 'auto_update' is enabled but not found" on every display start with auto-update or a dim schedule on; the reserved plugin-id check missed auto_update, sync, location and the rest; and ConfigManager's (uncalled) orphan cleanup would have deleted display, schedule and auto_update. All three now read src/core_config_keys.py, which also gains CORE_SECRETS_KEYS for the github/youtube secrets sections. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(web): partial JSON saves to /config/main change only what they send A JSON body with one field reset every checkbox in the sections it touched: the MQTT bridge's brightness slider turned off disable_hardware_pulsing, inverse_colors, show_refresh_rate and use_short_date_format, and a timezone-only save turned off web-UI autostart and weekly auto-updates. Missing-means-unchecked now applies only to form posts: form-encoded bodies and the v3 forms, which mark themselves with a hidden __form_section input. Also on the config routes: - vegas_min/max_cycle_duration no longer match the generic *_duration rule, so they stop landing in display_durations and a blank one no longer rejects the whole Display save; - saving from the Raw JSON editor calls start_setup_if_needed like the General form, so enabling auto-update there finishes its setup; - the schedule and dim-schedule POSTs accept the per-day days.<day> shape their GETs return, as well as the flat form keys. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(scripts): install plugin dependencies from the configured plugins directory install_plugin_dependencies.sh scanned only plugins/, but the Plugin Store installs into plugin_system.plugins_directory (default plugin-repos), so the documented "Recommended" fix found 0 plugins on every store install. It now reads plugins_directory from config/config.json (relative to the project root or absolute, default plugin-repos) and also scans plugins/ for dev symlinks, installing a plugin reached through both only once. With set -e alone, `pip ... | tee` took tee's exit status, so a failed pip install was reported as success; set -o pipefail. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs: replace stale API names, line numbers and the api_v3.py path - ADVANCED_FEATURES: StreamManager methods that exist (get_next_segment, take_next_group, refresh, advance_cycle, ...), and the real on-demand status envelope ({status, data: {state, service}}) - app.py:199 / :144 / :607-619 line citations and web_interface/blueprints/api_v3.py (now a package) replaced with file and function names in ADVANCED_FEATURES, CONFIG_DEBUGGING, PLUGIN_ARCHITECTURE_SPEC, PLUGIN_QUICK_REFERENCE, PLUGIN_CONFIGURATION_TABS, TROUBLESHOOTING and web_interface/README - CONFIG_DEBUGGING: partial /config/main saves change only sent keys; use /config/raw/main to replace the file; describe where validation runs - TROUBLESHOOTING: clear_cache.py needs --clear-all (no args only prints usage) Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(scripts): verify the web interface that actually ships, on port 5000 verify_installation.sh failed every healthy install: it required the long-removed web_interface_v2.py and looked for a listener on port 5001, while the web interface binds 5000 (web_interface/start.py). It now checks the files ledmatrix-web.service runs (start_web_conditionally.py, web_interface/start.py, app.py) and port 5000. verify_web_ui.sh had the same 5001 port in its listen check, HTTP probe and printed URLs. Port matches are anchored so :50001 no longer counts as :5000. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(plugins): one display-size contract: display_manager.width/height CLAUDE.md (#580) says to read display_manager.width/height because matrix is None when hardware init fails; the development guide, the safety-harness doc and two DisplayManager docstrings still recommended matrix.width/height. The bundled starlark-apps plugin read matrix.width unguarded, so its magnify recommendation and frame scaling raised in fallback mode (e.g. after the Pi 5 hardware refusal). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(install): make install_service.sh --help print usage instead of installing install_service.sh parsed no arguments, so `sudo ./scripts/install/ install_service.sh --help` (presented as harmless in MIGRATION_GUIDE.md) rewrote ledmatrix.service, ledmatrix-web.service and both update-verify units and enabled/started them. It now handles -h/--help (usage, exit 0, no changes) and rejects any other argument with exit 2 before doing anything. Running it with no arguments, as first_time_install.sh does, is unchanged. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(scroll): describe the fixed-step model and document frame_hold Since #545 a crisp speed from scroll_config.configure() makes the helper advance a fixed whole-pixel step per presented frame with no clock, and the display manager's frame hold is part of the speed. The docs still described the removed wall-clock model: - scroll_config's module and configure() docstrings said speed is applied in time-based mode and that omitting the hold "falls back to fractional pixels"; omitting it actually runs the scroll frame_hold times too fast. - SCROLL_PERFORMANCE.md said ScrollHelper accumulates elapsed time in both modes, and read a 20 ms stats median as missed refreshes although that is a healthy 50 px/s (hold 2) scroll. It now explains the fixed step, the hold-dependent healthy median, that target_fps plays no part, and that a hand-added scroll_pixels_per_second loses to a schema-default pair. - PLUGIN_API_REFERENCE.md documented set_scrolling_state(is_scrolling) without frame_hold; it now documents the parameter (core 3.4.0) with a configure() + set_scrolling_state example. - update_scroll_position/set_scroll_speed and set_scrolling_state docstrings say the same. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(config): mark target_fps legacy; describe what Vegas scroll_delay does - General tab "Scroll Frame Rate" (target_fps) is labelled legacy: after the sports_scroll fix nothing in core scrolling reads it. The field and its API validation stay so saved configs and plugins that read global_config['target_fps'] keep working. CONFIG_REFERENCE says the same. - Vegas frame_based_scrolling/scroll_delay were described as frame-count stepping at ~50 FPS. Neither steps nor sets a frame rate: frame-based mode converts the speed to px per scroll_delay, clamps it to 0.1-5, and still advances by elapsed time, so the applied speed is clamp(scroll_speed * scroll_delay, 0.1, 5) / scroll_delay px/s. The config comments, render_pipeline comment and CONFIG_REFERENCE rows now say so. No behaviour change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(deps): describe how plugin dependencies are really installed The guides said the web service runs as root, that installs pick --user from os.geteuid(), and quoted a warning and a PluginManager._install_plugin_dependencies() method that don't exist. The web unit runs as the installing user; store installs go through install_requirements_file() and sudo safe_pip_install.sh (root), with a user-level fallback that says so, and load-time installs run in the display service's own (root) interpreter. Manual paths now use the configured plugins directory (plugin-repos/ by default) instead of plugins/, which store installs no longer use, and install_plugin_dependencies.sh is described as scanning that directory. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(update): count local changes one way for the preflight and the pull The automatic update's preflight ignored mode-only changes and anything whose status line contained plugins/ or plugin-repos/, then promised "Automatic updates will not stash your changes". perform_core_update used plain git status (modes count) and ignored only 'plugins/', then ran 'git stash push -- :!plugins', which nothing ever pops. So an edit to a bundled plugin under plugin-repos/, or the installer's chmods on tracked scripts, passed the preflight and was stashed away for good. - auto_update.local_changes() is the one predicate both use: core.fileMode=false, porcelain -z, and plugins/ and plugin-repos/ excluded by leading folder rather than substring (a core file under web_interface/static/v3/js/plugins/ now counts). - Update Code's explicit stash leaves out both plugin folders; the pull's --autostash carries their edits and mode changes across and reapplies them. - The automatic updater calls perform_core_update(stash_local_changes= False), which refuses instead of stashing edits that appeared after the preflight; update_core reports that as 'blocked'. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(scripts): diagnostics follow the web autostart default and api_v3 package #556 made a missing web_display_autostart mean "start" (only an explicit false/off keeps the web interface down), but the diagnostics still said otherwise: diagnose_web_ui.sh reported a missing key as "defaults to false", diagnose_web_interface.sh said the web interface "will not start unless this is set to true" and recommended enabling it, and debug_web_manual.py printed False. Troubleshooting a down web UI pointed users at a non-cause. Both shell scripts now evaluate the setting with the launcher's own autostart_enabled() (inline fallback if it cannot be imported) and report on / off / not set (on) / unparseable config; debug_web_manual.py uses the same function. They also check web_interface/blueprints/api_v3/ __init__.py: api_v3.py became a package in #553, so every healthy checkout was reported as missing a file. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(install): what install_service.sh installs; verify script port; no sudo for --help install_service.sh installs and starts ledmatrix, ledmatrix-web and the update-verify units, not only ledmatrix.service (systemd/README.md, README.md). MIGRATION_GUIDE presented 'sudo install_service.sh --help' as a harmless check; it now shows --help without sudo and warns what a real run does. SSH_UNAVAILABLE_AFTER_INSTALL: verify_installation.sh checks the web interface on port 5000. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(changelog): note update-all, plugin system settings and script fixes Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(display): size the preview after orientation and pixel mappers display_geometry.physical_size claimed to give DisplayManager's answer but only computed cols*chain x rows*parallel. RGBMatrix.width/height are measured after the library's pixel mappers, so a Rotate:90 / orientation 90 chain previewed 128x32 for a 32x128 panel and a U-mapper chain of four 256x32 for 128x64. Model the built-in mappers' size effect as the pinned lib/pixel-mapper.cc does (Rotate, U-mapper, V-mapper, StackToRow, Remap; Mirror and unknown names leave it alone), and move the orientation composition here so DisplayManager and the preview share it. The module docstring no longer claims the sync handshake uses it; that imports only DEFAULT_CHAIN_LENGTH. Audit finding F18. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(display): refuse settings the rgbmatrix library aborts on, on every board The library answers several settings with a NULL matrix or abort() rather than an error, so the display service crash-looped (Restart=on-failure) instead of reaching fallback mode: rows above 64, chain_length above 255 (uint8_t binding setter, documented as "no upper limit"), a misspelled hardware_mapping, and parallel 2-3 on a single-output mapping, reachable from the Display form on the default adafruit-hat(-pwm) mapping. #586 only guarded the Pi 5 subset. - src/matrix_support.py holds the rules for every board (Options::Validate ranges, binding integer types, mapping names and outputs from lib/hardware-mapping.c) plus the Pi 5 ones, and is the one source of the API's numeric ranges. - DisplayManager checks them before building options and raises MatrixSettingsRefused, so a hand-edited config falls back with a logged, reported reason. Emulator mode only warns. - The config API refuses them with a 400 naming the setting; combinations are checked against stored values but reported only when the request sets a field involved. - The hardware status file gains "cause" (settings/library/forced). The fallback log and Display banner give the Pi 5 rebuild hint only for a library failure instead of rebuild + gpio_slowdown advice for every failure; one Pi 5 slowdown recommendation (1-3, start at 1). - The Display form offers classic/classic-pi1 and orientation 90/270 and renders any other stored mapping selected with a warning, so an unrelated save no longer rewrites them; the API accepts 90/270. Audit findings F03, F16, F19, F21. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(display): library limits, template defaults and Pi 5 slowdown - rows 8-64, chain_length 1-255, parallel limited by the mapping's outputs, classic/classic-pi1 mappings and orientation 90/270 documented. - Defaults are the config.template.json values: config migration adds missing keys from the template, so the listed "code defaults" never applied. - One Raspberry Pi 5 gpio_slowdown recommendation: 1-3 in PIO mode, starting at 1. - Troubleshooting describes the refused-settings fallback, and CHANGELOG corrects the Unreleased "no upper limit" entry. Audit findings F19, F20, F21. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(scripts): scroll_speeds.py opens the panel with the service's options --measure and --demo built RGBMatrixOptions from a private copy of the display service's builder that had drifted: gpio_slowdown came from display.hardware (default 2) instead of display.runtime (default 3), and rp1_rio, panel_type, disable_hardware_pulsing, inverse_colors, pixel_mapper_config and orientation were skipped, with different defaults (hardware_mapping "regular", pwm_bits 11). A panel needing a high slowdown was measured -- or garbled -- in a setup the service never drives. The option filling in DisplayManager._setup_matrix moves, unchanged, into DisplayManager.apply_matrix_options(options, config), which _setup_matrix calls and the script reuses (overriding only limit_refresh_rate_hz for --measure). The script now loads the whole config rather than the hardware block. Tests pin the script's options to the service's attribute for attribute. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(scripts): scroll_speeds.py recommends keys the resolver honours The ladder ended by telling users to set display_options.scroll_pixels_per_second. scroll_config ranks that key below the scroll_speed + scroll_delay pair, deliberately, and several plugin schemas default the pair into config, so the advised key was silently ignored (a schema-default 1/0.02 pair plus an advised 66 still resolved to 50 px/s). The advice is now the pair that selects the crisp speed exactly (pixels_per_frame every frame_hold/refresh seconds), explains that the pair outranks scroll_pixels_per_second, and gives the scoreboards' per-league scroll_settings.scroll_speed (px/s) form. Tests resolve the printed pair over a schema-default pair and check it lands on the advertised speed and hold. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs: withdraw the target_fps claim for sports_scroll; fix the Vegas speed formula - SPORTS_UNIFICATION.md still presented honouring global target_fps as sports_scroll's added behaviour and its one user-visible gain; note that it was withdrawn because it had become a speed multiplier. - ADVANCED_FEATURES.md gave Vegas scrolling as (scroll_speed / target_fps) * elapsed; the real rule is scroll_speed px/s by elapsed time, through a 0.1-5 px per scroll_delay clamp when frame_based_scrolling is on. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(changelog): scroll model fixes Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(dev): link-github links plugins from the ledmatrix-plugins monorepo link-github <name> cloned https://github.com/ChuckBuilds/ledmatrix-<name>.git, and those per-plugin repositories no longer exist: official plugins are directories in the ledmatrix-plugins monorepo. It now clones (or pulls) the monorepo once into the dev directory, finds plugins/<name>, plugins/ledmatrix-<name> or the plugin whose manifest id is <name>, and links it under its manifest id. With an explicit repo URL it still links a single-repository plugin as before. dev_plugins.json: github_user is honoured again (monorepo owner, e.g. a fork), plus plugins_repo and plugins_branch; github_pattern, which was documented but never read, is dropped and warned about. Ships dev_plugins.json.example and git-ignores dev_plugins.json, both of which the guide promised. Reading JSON falls back to python3 when jq is missing (get_plugin_id silently returned nothing without jq). update/status/list find the git checkout above a monorepo plugin directory (its .git is not in the plugin dir), and update pulls a shared checkout once. status no longer exits 1 when nothing is broken. Docs: PLUGIN_DEVELOPMENT_GUIDE (quick start, link-github, configuration, workflow, store integration, hello-world link, submission), and the nonexistent scripts/git-hooks/pre-push-plugin-version and scripts/bump_plugin_version.py replaced with the real rule: bump the manifest version and run update_registry.py. scripts/dev/README.md and CLAUDE.md updated to match. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(scripts): monorepo workspace layout; fix_perms and install READMEs MULTI_ROOT_WORKSPACE_SETUP described one sibling repository per plugin; setup_plugin_repos.py links ../ledmatrix-plugins/plugins/* into plugin-repos/ and update_plugin_repos.py pulls only the monorepo, and the workspace file opens LEDMatrix plus ../ledmatrix-plugins. scripts/fix_perms/README.md listed cache directories fix_cache_permissions.sh never touches and a 'ledmatrix' service user that doesn't exist (also in scripts/install/README.md); adds safe_pip_install.sh. install/README: install_service.sh installs the web and update-verify units too. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(update): keep the rollback's pip retries inside the unit time limit The health check reinstalled the previous requirements by trying the next bash path after any failure, including a 600 s pip timeout. Two files, two paths: up to 40 minutes of pip alone, while systemd stops ledmatrix-update-verify.service at TimeoutStartSec=30min -- killing the rollback half-way and leaving the update 'verifying' until the web UI calls it lost. - Like permission_utils.install_requirements_file, only a sudo refusal moves on to the next bash; a pip that ran and failed or timed out is not repeated. The refusal wording is one list (permission_utils.SUDO_REFUSAL_PHRASES), mirrored in the stdlib-only verifier and pinned equal by a test. - All reinstalls in one rollback share a 600 s budget. - WORST_CASE_SECONDS adds up every timeout on the longest path (27.5 min); a test holds it under the unit's TimeoutStartSec and that under the web UI's VERIFY_LOST_SECONDS. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(plugins): prepare plugin configs one way for load, saves, GET, hot reload and dev tools Plugin config was prepared differently depending on how it arrived: - JSON POST /plugins/config built a partial body on schema defaults, so {"enabled": true} reset every other setting of the plugin. It now merges onto the stored section first, as the form path already did. - Legacy-boolean normalization (#588) ran only at load: GET /plugins/config returned the raw boolean, posting it back failed validation, and hot reload handed plugins the raw section (a legacy dynamic_duration: true came back as a boolean). schema_manager.prepare_plugin_config (normalize, then defaults) is now used by PluginManager.load_plugin, both save paths, GET, the save notifications and DisplayController's hot-reload callback. - The JSON save's filter kept only enabled/display_duration/live_priority and dropped a submitted skin, skin_options or vegas_* tuning key. There is now one core-owned per-plugin list, schema_manager.CORE_PLUGIN_PROPERTIES, used by validation and by the save filter; PluginManager's CORE_OWNED_CONFIG_KEYS is its vegas subset. - Plugin sections posted to /config/main were stored verbatim, including values /plugins/config rejects. They now go through the same preparation (_prepare_plugin_config_for_save, extracted from save_plugin_config), and a failing section rejects the whole save before anything is written. - dev_server read only top-level defaults and let a schema enabled:false win; build_full_config shallow-merged overrides, dropping sibling defaults; the harness extracted defaults differently from the device. loading.build_config now uses the device's extraction and preparation, and dev_server, check_plugin, render_plugin and the harness all use it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(mqtt-bridge): brightness changes apply live and touch nothing else The display service's hot reload applies a saved brightness within a few seconds, and /config/main no longer resets other display settings on a brightness-only JSON body. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(changelog): automatic update hardening Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(config): rewrite PLUGIN_CONFIG_ARCHITECTURE for the v3 web UI It described web_interface_v2.py and index_v2.html (both gone), client-side form generation, one POST per field with {key, value}, and 'no nested objects'. The v3 UI renders plugin forms server-side from the schema (pages_v3 partial + plugin_config.html macros, nested sections and x-widgets), posts the whole form once, and save_plugin_config() merges onto the stored section, validates, splits x-secret fields and notifies the plugin. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(mqtt): brightness saves apply via hot reload and leave other settings alone The bridge README said brightness is applied on the display's next restart; the display controller's config hot reload applies it within seconds. It also now states that the bridge's partial JSON save changes only brightness (the /config/main merge fix in this change set). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(update): don't log pip's output from the health check's reinstall pip can echo a private index URL with embedded credentials; permission_utils redacts it, the stdlib-only verifier cannot, so it logs the exit code only. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(config): mark the plugin_system toggles as unused legacy keys auto_discover, auto_load_enabled and development_mode are read by nothing and leave the General tab in this change set (F40). CONFIG_REFERENCE said they were read by the plugin loader; PLUGIN_CONFIGURATION_GUIDE and the REST reference listed them as live settings. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(changelog): docs and developer tools group Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(web): legacy plugin-system toggles no longer count as a General save auto_discover, auto_load_enabled and development_mode have left the General form, so a post carrying only one of them is not a general-settings save and must not treat web_display_autostart and auto_update as unchecked. The plugin_system block itself is left as on main for the branch that reworks it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(changelog): config-save and plugin-config preparation fixes Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(claude): re-check matrix_support.py rules when the library submodule is bumped Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix: address Codacy findings on the core audit PR - plugin_manager.prepare_plugin_config: when the fallback legacy-boolean pass also fails, log a warning instead of a bare except/pass. - api_client.js: request() refuses any endpoint that is not a plain path under /api/v3 ("//host", backslashes, ".." or "." segments, whitespace, control characters) with INVALID_ENDPOINT before calling fetch(), and plugin ids are URL-encoded wherever they are put into a URL (also in the app-shell batch load). - test_update_all.js: pins both against the shipped client. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(web): check endpoint control characters without a control-character regex Codacy (ESLint no-control-regex, Biome noControlCharactersInRegex) flags the \x00-\x1f range in checkEndpoint's regex. Test the char codes instead; the endpoints refused are unchanged. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * test(auto-update): make the seed script executable on disk, not only in the index On Linux Repo.publish() commits with -a, which recorded scripts/run.sh as 100644 upstream because the seed file was never chmod +x. The pull then brought in the same mode the installer chmod had made locally, so installer_chmod saw no mode change left to check. The updater was fine: with the upstream commit at 100755 the --autostash carries the device's chmod across. Verified under Linux (WSL, git 2.43): the old helper fails exactly as CI did, the fixed one passes all 63 tests in the file. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
46 KiB
LEDMatrix REST API Reference
Reference for the REST API served by the LEDMatrix web interface.
Base URL: http://your-pi-ip:5000/api/v3
Most endpoints answer JSON in this envelope:
{
"status": "success" | "error",
"data": { ... },
"message": "Optional message"
}
Not every endpoint follows it exactly. Where a response puts fields at the
top level instead of under data (install-from-url, registry-from-url, the
auth endpoints, upload endpoints, system/git-info, system/check-update),
the entry below says so.
Table of Contents
- Configuration
- Display Control
- Plugins
- Plugin Store
- System
- Backup and Restore
- Fonts
- Cache
- WiFi
- Streams
- Logs
- Error tracking
- Health and Status
- Schedule (dim/power)
- Integrations
- Plugin-specific endpoints
- Starlark Apps
- Skins
The API blueprint is the
api_v3package inweb_interface/blueprints/api_v3/(one module per area:config.py,display.py,plugins.py,system.py,backup.py,fonts.py,misc.py,wifi.py,starlark.py).web_interface/app.pyregisters it at/api/v3(app.register_blueprint(api_v3, url_prefix='/api/v3')). The three SSE endpoints (/api/v3/stream/*) are defined directly on the Flask app inapp.py(stream_stats,stream_display,stream_logs).test/fixtures/api_v3_url_map.jsonis the canonical list of blueprint routes (116 URL rules); a test fails if the code and that fixture differ.
Configuration
Get Main Configuration
GET /api/v3/config/main
Return config/config.json. Fields whose names look like credentials
(api_key, token, password, secret, ...) are blanked to "" in the
response; config/config_secrets.json values are never included.
Response:
{
"status": "success",
"data": {
"timezone": "America/New_York",
"location": {
"city": "New York",
"state": "NY",
"country": "US"
},
"display": { ... },
"plugin_system": { ... }
}
}
Save Main Configuration
POST /api/v3/config/main
Update the main configuration. Accepts JSON (Content-Type: application/json)
or form data. The body uses the web UI's flat field names, which the handler
maps into the nested config:
| Fields | Stored at |
|---|---|
timezone, city, state, country |
timezone, location.* |
web_display_autostart, auto_update_enabled |
web_display_autostart, auto_update.enabled |
plugins_directory (and the unused legacy flags auto_discover, auto_load_enabled, development_mode, stored only when sent) |
plugin_system.* |
target_fps (30-200) |
target_fps |
rows, cols, chain_length, parallel, brightness, hardware_mapping, pwm_bits, led_rgb_sequence, panel_type, pixel_mapper_config, disable_hardware_pulsing, inverse_colors, show_refresh_rate, ... |
display.hardware.* |
gpio_slowdown, rp1_rio |
display.runtime.* |
use_short_date_format |
display.use_short_date_format |
max_dynamic_duration_seconds |
display.dynamic_duration.max_duration_seconds |
double_sided_*, vegas_*, sync_* |
display.double_sided, display.vegas_scroll, sync |
<name>_duration, default_duration, duration__<mode> |
display.display_durations.* |
plugin_rotation_order (list of plugin ids) |
display.plugin_rotation_order |
Any other top-level key is deep-merged into the config as given.
A JSON body changes only the keys it contains; everything else keeps its
stored value. (Form posts from the web UI send every field of a tab, and
there an unchecked checkbox — which the browser omits — is saved as
false.)
Request Body (JSON):
{
"timezone": "America/New_York",
"city": "New York",
"brightness": 90
}
Response:
{
"status": "success",
"message": "Configuration saved successfully"
}
Invalid values (e.g. an out-of-range target_fps, a hardware option the
Raspberry Pi 5 driver cannot use) are rejected with 400 and nothing is
saved.
Get Schedule Configuration
GET /api/v3/config/schedule
Retrieve the current on/off schedule.
Response:
{
"status": "success",
"data": {
"enabled": true,
"mode": "global",
"start_time": "07:00",
"end_time": "23:00"
}
}
Per-day mode response:
{
"status": "success",
"data": {
"enabled": true,
"mode": "per-day",
"days": {
"monday": {
"enabled": true,
"start_time": "07:00",
"end_time": "23:00"
},
"tuesday": { ... }
}
}
}
Save Schedule Configuration
POST /api/v3/config/schedule
Replace the schedule configuration.
Request Body (Global mode):
{
"enabled": true,
"mode": "global",
"start_time": "07:00",
"end_time": "23:00"
}
Request Body (Per-day mode, flat form-field names):
{
"enabled": true,
"mode": "per-day",
"monday_enabled": true,
"monday_start": "07:00",
"monday_end": "23:00",
"tuesday_enabled": true,
"tuesday_start": "08:00",
"tuesday_end": "22:00"
}
A day whose <day>_enabled key is absent counts as enabled, with default
times 07:00-23:00. At least one day must be enabled.
Response:
{
"status": "success",
"message": "Schedule configuration saved successfully"
}
Get Secrets Configuration
GET /api/v3/config/secrets
Retrieve config/config_secrets.json with every set value replaced by eight
bullet characters ("••••••••"). Empty values and YOUR_* placeholders
are returned as-is, so a client can tell "set" from "not set".
Response:
{
"status": "success",
"data": {
"ledmatrix-weather": {
"api_key": "••••••••"
}
}
}
Save Raw Configuration
POST /api/v3/config/raw/main
Replace config/config.json with the JSON body (advanced use only).
POST /api/v3/config/raw/secrets
Save the secrets file (advanced use only). Masked values ("••••••••")
and blank strings in the body are dropped, and the rest is merged onto the
stored secrets, so posting back the GET response unchanged changes nothing.
A secret cannot be cleared by blanking it here.
Display Control
Get Current Display
GET /api/v3/display/current
Get the latest display snapshot as a base64 PNG (image is null when no
snapshot is available).
Response:
{
"status": "success",
"data": {
"timestamp": 1234567890.123,
"width": 128,
"height": 32,
"image": "base64_encoded_image_data"
}
}
Get Current Display Status
GET /api/v3/display/current-status
The mode and plugin the display service is currently showing, as published by the display process (stale after 120 seconds).
Response:
{
"status": "success",
"data": {
"mode": "nfl_live",
"plugin_id": "football-scoreboard",
"last_updated": 1234567890.123
}
}
When nothing has been published, every field is null.
List Display Modes
GET /api/v3/display/modes
Every display mode that can be requested on-demand, with the plugin that owns it. This is the list the force-display dialog offers.
Send the reported plugin_id alongside mode when starting an on-demand
display: /display/on-demand/start falls back to find_plugin_for_mode when
plugin_id is omitted, and that lookup only sees modes declared in a static
manifest — a plugin whose modes are generated (each installed Starlark app is
one) returns 404 there.
Triggers plugin discovery, which is otherwise lazy — so a caller that never opens the dashboard still gets the full list.
Query Parameters:
include_disabled(optional):1to include modes belonging to disabled plugins. They are still valid on-demand targets — the controller enables the plugin for the duration of the request — and are reported with"enabled": false.
Response:
{
"status": "success",
"data": {
"modes": [
{
"mode": "nfl_live",
"plugin_id": "football-scoreboard",
"plugin_name": "Football Scoreboard",
"name": "nfl_live",
"enabled": true
},
{
"mode": "clock-simple",
"plugin_id": "clock-simple",
"plugin_name": "Simple Clock",
"name": "Simple Clock",
"enabled": true
}
]
}
}
name is a label for a dropdown: a single-mode plugin's own name, or the raw
mode string for a multi-mode plugin, since there is no per-mode name anywhere.
On-Demand Display Status
GET /api/v3/display/on-demand/status
Get the current on-demand display state.
Response:
{
"status": "success",
"data": {
"state": {
"active": true,
"plugin_id": "football-scoreboard",
"mode": "nfl_live",
"duration": 45,
"pinned": true,
"status": "running",
"last_updated": 1234567890.123
},
"service": {
"active": true,
"returncode": 0,
"stdout": "active",
"stderr": ""
}
}
}
With no on-demand request, state is
{"active": false, "status": "idle", "last_updated": null}.
Start On-Demand Display
POST /api/v3/display/on-demand/start
Request a specific plugin to display on-demand.
Request Body:
{
"plugin_id": "football-scoreboard",
"mode": "nfl_live",
"duration": 45,
"pinned": true,
"start_service": true
}
Parameters (at least one of plugin_id and mode is required):
plugin_id(string, optional): Plugin identifiermode(string, optional): Display mode name (plugin_id inferred if not provided)duration(number, optional): Duration in seconds (0 = until stopped)pinned(boolean, optional): Pin display (pause rotation)start_service(boolean, optional): (Re)start the display service so it picks the request up (default: true)
Response:
{
"status": "success",
"data": {
"request_id": "uuid-here",
"plugin_id": "football-scoreboard",
"mode": "nfl_live",
"duration": 45,
"pinned": true,
"service": { "active": true, "returncode": 0, "stdout": "", "stderr": "" }
}
}
service is null when start_service is false.
Stop On-Demand Display
POST /api/v3/display/on-demand/stop
Stop the current on-demand display.
Request Body:
{
"stop_service": false
}
Parameters:
stop_service(boolean, optional): Also stop the display service (default: false)
Response:
{
"status": "success",
"data": {
"request_id": "uuid-here",
"service": null
}
}
Plugins
Get Installed Plugins
GET /api/v3/plugins/installed
List all installed plugins with their status and metadata.
Response:
{
"status": "success",
"data": {
"plugins": [
{
"id": "football-scoreboard",
"name": "Football Scoreboard",
"version": "1.2.3",
"latest_version": "1.2.4",
"update_available": true,
"author": "ChuckBuilds",
"category": "Sports",
"description": "NFL and NCAA Football scores",
"tags": ["sports", "football", "nfl"],
"enabled": true,
"verified": true,
"loaded": true,
"state": "loaded",
"error_info": null,
"last_updated": "2025-01-15T10:30:00Z",
"last_commit": "abc1234",
"last_commit_message": "feat: Add live game updates",
"branch": "main",
"web_ui_actions": [],
"vegas_mode": null,
"vegas_content_type": null
}
]
}
}
Get Plugin Configuration
GET /api/v3/plugins/config?plugin_id=<plugin_id>
Get a plugin's configuration, with schema defaults filled in for keys that
are not stored. data is the configuration object itself.
Query Parameters:
plugin_id(required): Plugin identifier
Response:
{
"status": "success",
"data": {
"enabled": true,
"display_duration": 30,
"favorite_teams": ["TB", "DAL"]
}
}
Save Plugin Configuration
POST /api/v3/plugins/config
Update a plugin's configuration. With a JSON body, the keys in config are
merged onto the plugin's stored configuration: keys you do not send keep
their stored values. Fields the schema marks "x-secret": true are written
to config/config_secrets.json instead of config.json. The web UI posts
form data instead (?plugin_id= in the query string, fields as form fields).
Request Body:
{
"plugin_id": "football-scoreboard",
"config": {
"display_duration": 30,
"favorite_teams": ["TB", "DAL"]
}
}
Response:
{
"status": "success",
"message": "Plugin football-scoreboard configuration saved successfully"
}
A config that fails schema validation is rejected with 400 and nothing is
saved.
Get Plugin Schema
GET /api/v3/plugins/schema?plugin_id=<plugin_id>
Get the JSON schema for a plugin's configuration. A plugin without a
config_schema.json gets a minimal default schema.
Query Parameters:
plugin_id(required): Plugin identifier
Response:
{
"status": "success",
"data": {
"schema": {
"type": "object",
"properties": {
"enabled": {
"type": "boolean",
"default": true
},
"display_duration": {
"type": "number",
"minimum": 1,
"maximum": 300
}
}
}
}
}
Reset Plugin Configuration
POST /api/v3/plugins/config/reset
Reset a plugin's configuration to its schema defaults.
Request Body:
{
"plugin_id": "football-scoreboard",
"preserve_secrets": true
}
Response:
{
"status": "success",
"message": "Plugin football-scoreboard configuration reset to defaults",
"data": { "config": { ... } }
}
Toggle Plugin
POST /api/v3/plugins/toggle
Enable or disable a plugin. A plugin_id of the form starlark:<app_id>
toggles a Starlark app.
Request Body:
{
"plugin_id": "football-scoreboard",
"enabled": true
}
Response:
{
"status": "success",
"message": "Plugin football-scoreboard enabled successfully"
}
Install Plugin
POST /api/v3/plugins/install
Install a plugin from the plugin store.
Request Body:
{
"plugin_id": "football-scoreboard",
"branch": "main"
}
branch is optional.
Response (queued; poll /plugins/operation/<operation_id>):
{
"status": "success",
"data": { "operation_id": "uuid-here" },
"message": "Plugin football-scoreboard installation queued"
}
When the operation queue is unavailable the install runs synchronously and
the response has only a message.
Uninstall Plugin
POST /api/v3/plugins/uninstall
Remove an installed plugin.
Request Body:
{
"plugin_id": "football-scoreboard",
"preserve_config": false
}
Response (queued):
{
"status": "success",
"data": { "operation_id": "uuid-here" },
"message": "Plugin uninstallation queued"
}
Update Plugin
POST /api/v3/plugins/update
Update a plugin to the latest version. Runs synchronously.
Request Body:
{
"plugin_id": "football-scoreboard"
}
Response:
{
"status": "success",
"message": "Plugin football-scoreboard updated ...",
"data": {
"last_updated": "2025-01-15T10:30:00Z",
"commit": "abc1234..."
}
}
Install Plugin from URL
POST /api/v3/plugins/install-from-url
Install a plugin directly from a GitHub repository URL. Runs synchronously.
Request Body:
{
"repo_url": "https://github.com/user/ledmatrix-my-plugin",
"branch": "main",
"plugin_path": null
}
Parameters:
repo_url(required): GitHub repository URLbranch(optional): Branch name (default:main, thenmaster)plugin_path(optional): Path within the repository, for monorepo pluginsplugin_id(optional): Plugin id, for monorepo installations
Response (fields at the top level):
{
"status": "success",
"message": "Plugin my-plugin installed successfully",
"plugin_id": "my-plugin",
"name": "My Plugin",
"branch": "main"
}
Load Registry from URL
POST /api/v3/plugins/registry-from-url
Load a plugins.json registry from a GitHub repository URL.
Request Body:
{
"repo_url": "https://github.com/user/ledmatrix-plugins"
}
Response (fields at the top level):
{
"status": "success",
"plugins": [
{
"id": "plugin-1",
"name": "Plugin One",
"description": "..."
}
],
"registry_url": "https://github.com/user/ledmatrix-plugins"
}
Get Plugin Health
GET /api/v3/plugins/health
Get health state for all installed plugins, keyed by plugin id.
Response:
{
"status": "success",
"data": {
"football-scoreboard": {
"plugin_id": "football-scoreboard",
"circuit_state": "closed",
"consecutive_failures": 0,
"total_failures": 2,
"total_successes": 1500,
"success_rate": 99.87,
"last_success_time": 1234567890.123,
"last_failure_time": 1234560000.0,
"last_error": null,
"is_healthy": true,
"degraded": false,
"degraded_reason": null,
"circuit_opened_time": null,
"half_open_start_time": null
}
}
}
Get Plugin Health (Single)
GET /api/v3/plugins/health/<plugin_id>
Health state for one plugin; data has the same fields as one entry above.
Answers 503 when health tracking is unavailable.
Reset Plugin Health
POST /api/v3/plugins/health/<plugin_id>/reset
Reset health state for a plugin (manual recovery).
Response:
{
"status": "success",
"message": "Health state reset for plugin football-scoreboard"
}
Get Plugin Metrics
GET /api/v3/plugins/metrics
Get resource usage metrics for all installed plugins, keyed by plugin id.
Response:
{
"status": "success",
"data": {
"football-scoreboard": {
"plugin_id": "football-scoreboard",
"memory_mb": 24.5,
"cpu_percent": 3.2,
"execution_time": 0.12,
"avg_execution_time": 0.1,
"min_execution_time": 0.05,
"max_execution_time": 0.9,
"call_count": 500,
"last_update_time": 1234567890.123,
"limits": {
"max_memory_mb": 50,
"max_cpu_percent": 50,
"max_execution_time": 5.0,
"warning_threshold": 0.8
}
}
}
}
limits (and usage percentages derived from it) appear only when limits
are configured for the plugin.
Get Plugin Metrics (Single)
GET /api/v3/plugins/metrics/<plugin_id>
Metrics for one plugin; data has the same fields as one entry above.
Reset Plugin Metrics
POST /api/v3/plugins/metrics/<plugin_id>/reset
Reset metrics for a plugin.
Get/Set Plugin Limits
GET /api/v3/plugins/limits/<plugin_id>
Get a plugin's resource limits. data is null when none are configured.
Response:
{
"status": "success",
"data": {
"max_memory_mb": 50,
"max_cpu_percent": 50,
"max_execution_time": 5.0,
"warning_threshold": 0.8
}
}
POST /api/v3/plugins/limits/<plugin_id>
Set a plugin's resource limits. The body replaces all four limits: a key you
omit is stored as no limit (warning_threshold defaults to 0.8).
Request Body:
{
"max_memory_mb": 50,
"max_cpu_percent": 50,
"max_execution_time": 5.0,
"warning_threshold": 0.8
}
Get Plugin State
GET /api/v3/plugins/state
Get the state manager's record for every plugin, keyed by plugin id. Pass
?plugin_id=<id> for one plugin (data is then that record).
Response:
{
"status": "success",
"data": {
"football-scoreboard": {
"plugin_id": "football-scoreboard",
"status": "loaded",
"enabled": true,
"version": "1.2.3",
"installed_at": "2025-01-15T10:30:00",
"last_updated": "2025-01-15T10:30:00",
"config_version": 1,
"metadata": {}
}
}
}
Reconcile Plugin State
POST /api/v3/plugins/state/reconcile
Reconcile plugin state across config, disk and the state manager.
Request Body (optional):
{
"force": false
}
Response:
{
"status": "success",
"message": "...",
"data": {
"inconsistencies_found": 1,
"inconsistencies_fixed": 1,
"inconsistencies_manual": 0,
"inconsistencies": [
{"plugin_id": "...", "type": "...", "description": "...", "fix_action": "..."}
],
"fixed": [ ... ],
"manual_fix_required": [ ... ]
}
}
Get Reconciliation Status
GET /api/v3/plugins/reconciliation-status
Result of the last startup reconciliation, as written by the display service.
Response:
{
"status": "success",
"data": {
"done": true,
"unresolved": []
}
}
Before a run has finished, data is {"done": false, "unresolved": []}.
Get Plugin Operation
GET /api/v3/plugins/operation/<operation_id>
Get status of a queued plugin operation (install, uninstall).
Response:
{
"status": "success",
"data": {
"operation_id": "uuid-here",
"operation_type": "install",
"plugin_id": "football-scoreboard",
"parameters": {},
"status": "completed",
"progress": 100,
"message": "Installation completed successfully",
"error": null,
"result": { ... },
"created_at": "2025-01-15T10:30:00",
"started_at": "2025-01-15T10:30:01",
"completed_at": "2025-01-15T10:30:20"
}
}
Get Operation History
GET /api/v3/plugins/operation/history?limit=50
Get the plugin operation audit log. data is a list.
Query Parameters:
limit(optional): Maximum number of records (default: 50)plugin_id(optional): Only records for this pluginoperation_type(optional): Only records of this type (install,update,enable, ...)
Response:
{
"status": "success",
"data": [
{
"operation_id": "uuid-here",
"operation_type": "install",
"plugin_id": "football-scoreboard",
"timestamp": "2025-01-15T10:30:00",
"status": "success",
"user": null,
"details": null,
"error": null
}
]
}
Clear Operation History
DELETE /api/v3/plugins/operation/history
Clear the operation audit log.
Execute Plugin Action
POST /api/v3/plugins/action
Execute an action declared in the plugin manifest's web_ui_actions. See
PLUGIN_WEB_UI_ACTIONS.md.
Request Body:
{
"plugin_id": "football-scoreboard",
"action_id": "refresh_games",
"params": {}
}
Response (fields at the top level; a script that prints JSON can return its own object instead):
{
"status": "success",
"message": "Action completed successfully",
"output": "script stdout"
}
Upload Plugin Assets
POST /api/v3/plugins/assets/upload
Upload images for a plugin. Stored under
assets/plugins/<plugin_id>/uploads/.
Request: Multipart form data
plugin_id(required): Plugin identifierfiles(required, repeatable, up to 10): PNG, JPEG, BMP or GIF images, 5 MB each, 50 MB total per plugin
Response (fields at the top level):
{
"status": "success",
"uploaded_files": [
{
"id": "uuid-here",
"filename": "image_1700000000_abcd1234.png",
"path": "assets/plugins/football-scoreboard/uploads/image_1700000000_abcd1234.png",
"size": 1024,
"uploaded_at": "2025-01-15T10:30:00Z"
}
],
"total_files": 3
}
Delete Plugin Asset
POST /api/v3/plugins/assets/delete
Delete an uploaded plugin image by its id (the id from upload or list).
Request Body:
{
"plugin_id": "football-scoreboard",
"image_id": "uuid-here"
}
List Plugin Assets
GET /api/v3/plugins/assets/list?plugin_id=<plugin_id>
List uploaded images for a plugin.
Query Parameters:
plugin_id(required): Plugin identifier
Response:
{
"status": "success",
"data": {
"assets": [
{
"id": "uuid-here",
"filename": "image_1700000000_abcd1234.png",
"path": "assets/plugins/football-scoreboard/uploads/image_1700000000_abcd1234.png",
"size": 1024,
"uploaded_at": "2025-01-15T10:30:00Z",
"original_filename": "logo.png"
}
]
}
}
Authenticate Spotify
POST /api/v3/plugins/authenticate/spotify
Spotify OAuth for the music plugin (ledmatrix-music; the plugin is fixed,
not taken from the body). Two steps: call with an empty body to get the
authorization URL, then call again with the URL Spotify redirected to.
Request Body (step 2):
{
"redirect_url": "http://127.0.0.1:8888/callback?code=..."
}
Response (step 1, fields at the top level):
{
"status": "success",
"message": "Authorization URL generated",
"auth_url": "https://accounts.spotify.com/authorize?..."
}
Step 2 returns status, message and the script's output.
Authenticate YouTube Music
POST /api/v3/plugins/authenticate/ytm
Run the music plugin's YouTube Music authentication script. No body. Returns
status, message and the script's output.
Upload Calendar Credentials
POST /api/v3/plugins/calendar/upload-credentials
Upload the Google OAuth client file for the calendar plugin.
Request: Multipart form data
file(required):credentials.json(JSON, max 1 MB)
Authenticate Calendar
POST /api/v3/plugins/calendar/authenticate
Google OAuth for the calendar plugin, in two steps. Step 1 (no body) returns the consent URL. Step 2 posts the URL Google redirected to (it fails to load in the browser, but its address carries the authorization code):
{
"redirect_url": "http://localhost/?code=..."
}
Requires credentials.json to have been uploaded first (400 otherwise).
Plugin Store
List / Search Store Plugins
GET /api/v3/plugins/store/list
List plugins from the registry and saved repositories. The same endpoint searches.
Query Parameters:
query(optional): Text search over name, description, idcategory(optional): Category filtertags(optional, repeatable): Tag filterfetch_commit_info(optional):falseto skip fetching commit metadata from GitHub (default: fetched)
Response:
{
"status": "success",
"data": {
"plugins": [
{
"id": "football-scoreboard",
"name": "Football Scoreboard",
"author": "ChuckBuilds",
"category": "Sports",
"description": "NFL and NCAA Football scores",
"tags": ["sports"],
"stars": 0,
"verified": true,
"repo": "https://github.com/ChuckBuilds/ledmatrix-plugins",
"last_updated": "2025-01-15",
"last_updated_iso": "2025-01-15T10:30:00Z",
"last_commit": "abc1234",
"last_commit_message": "...",
"last_commit_author": "...",
"version": "1.2.3",
"branch": "main",
"default_branch": "main",
"plugin_path": "plugins/football-scoreboard"
}
]
}
}
Get GitHub Status
GET /api/v3/plugins/store/github-status
Whether a GitHub token is configured and valid.
Response:
{
"status": "success",
"data": {
"token_status": "valid",
"authenticated": true,
"rate_limit": 5000,
"message": "GitHub API authenticated",
"error": null
}
}
token_status is none, valid or invalid; rate_limit is the nominal
hourly limit (60 unauthenticated), not a live count.
Refresh Plugin Store
POST /api/v3/plugins/store/refresh
Force refresh of the registry cache.
Response:
{
"status": "success",
"message": "Plugin store refreshed",
"plugin_count": 42
}
Get Saved Repositories
GET /api/v3/plugins/saved-repositories
Get the list of saved custom plugin repositories.
Response:
{
"status": "success",
"data": {
"repositories": [
{
"url": "https://github.com/user/ledmatrix-plugins",
"name": "ledmatrix-plugins",
"type": "registry"
}
]
}
}
Save Repository
POST /api/v3/plugins/saved-repositories
Save a custom plugin repository. Returns the updated list in
data.repositories.
Request Body:
{
"repo_url": "https://github.com/user/ledmatrix-plugins",
"name": "Custom Plugins"
}
Delete Saved Repository
DELETE /api/v3/plugins/saved-repositories
Remove a saved repository. Returns the updated list in data.repositories.
Request Body:
{
"repo_url": "https://github.com/user/ledmatrix-plugins"
}
System
Get System Status
GET /api/v3/system/status
Get system status and metrics (cached for 10 seconds).
Response:
{
"status": "success",
"data": {
"timestamp": 1234567890.123,
"uptime": "3d 4h",
"uptime_seconds": 273600,
"service_active": true,
"cpu_percent": 25.5,
"memory_used_percent": 45.2,
"memory_total_mb": 3794.0,
"memory_used_mb": 1715.0,
"memory_available_mb": 1900.0,
"cpu_temp": 45.0,
"disk_used_percent": 60.0,
"disk_total_gb": 29.0,
"disk_used_gb": 17.4
}
}
Get System Version
GET /api/v3/system/version
Get LEDMatrix repository version.
Response:
{
"status": "success",
"data": {
"version": "v2.4-10-g1234567"
}
}
Check for Update
GET /api/v3/system/check-update
Whether origin/main has commits the checkout lacks. Cached briefly.
Fields at the top level (no envelope):
{
"update_available": true,
"remote_sha": "abc123...",
"commits_behind": 3
}
When git cannot run the check, the response also carries
"check_failed": true and an error explaining why.
Automatic Update Status
GET /api/v3/system/auto-update
Weekly automatic-update status for the General tab and the Overview banner:
last_run, summary, status, next_due, alert, alert_id,
verifier_installed, setup_status, setup_message, verifying (in
data).
POST /api/v3/system/auto-update/dismiss
Hide the current automatic-update alert until a new one replaces it.
{
"alert_id": "..."
}
Git Info
GET /api/v3/system/git-info
Branch, dirty state, recent commits and remote for the Tools tab. Fields at
the top level: branch, dirty, status, recent_commits, remote_url
(credentials scrubbed), upstream, can_pull.
Git Branches
GET /api/v3/system/git-branches
Fetches origin and lists branches to switch to: current, upstream,
local (list), remote_only (list), at the top level.
Execute System Action
POST /api/v3/system/action
Execute system-level actions. JSON or form data.
Request Body:
{
"action": "restart_display_service"
}
Available Actions:
start_display: Start the display servicestop_display: Stop the display servicerestart_display_service: Restart the display servicerestart_web_service: Restart the web interface serviceenable_autostart: Enable display service autostartdisable_autostart: Disable display service autostartreboot_system: Reboot the Raspberry Pishutdown_system: Power off the Raspberry Pigit_pull: Update LEDMatrix from git (the Update button)checkout_branch: Switch branch; takesbranchand optionalstashforce_git_reset:git reset --hard origin/maininstall_base_requirements: pip installrequirements.txtandweb_interface/requirements.txtinstall_plugin_requirements: pip install every plugin'srequirements.txtclear_pycache: Delete__pycache__directories
Response (service actions):
{
"status": "success",
"message": "Action completed"
}
A failed service action returns "status": "error" with returncode and
stderr. git_pull returns message, restart_required and
dependency_failures; the install actions return output or details.
Backup and Restore
Backups are ZIP files kept in the backup export directory.
Preview
GET /api/v3/backup/preview
Summary of what a new backup would include.
List
GET /api/v3/backup/list
Stored backups, newest first. data is a list of
{"filename", "size", "created_at"}.
Export
POST /api/v3/backup/export
Create a backup. Returns {"status": "success", "filename": "..."}.
Validate
POST /api/v3/backup/validate
Check an uploaded backup and return its manifest in data.
Request: Multipart form data
backup_file(required): the ZIP
Restore
POST /api/v3/backup/restore
Restore an uploaded backup.
Request: Multipart form data
backup_file(required): the ZIPoptions(optional): JSON object; keysrestore_config,restore_secrets,restore_wifi,restore_fonts,restore_plugin_uploads,reinstall_plugins(each defaults totrue; unknown keys are rejected)
A partial restore answers 500 with "status": "error", a message listing
what did and didn't restore, and the result in data.
Download
GET /api/v3/backup/download/<filename>
Download a stored backup.
Delete
DELETE /api/v3/backup/<filename>
Delete a stored backup.
Fonts
Get Font Catalog
GET /api/v3/fonts/catalog
Fonts in assets/fonts/, keyed by file name without extension.
Response:
{
"status": "success",
"data": {
"catalog": {
"press_start": {
"filename": "press_start.ttf",
"family_name": "Press Start 2P",
"display_name": "Press Start 2P",
"path": "assets/fonts/press_start.ttf",
"type": "ttf",
"is_system": true,
"scalable": true,
"native_size": null,
"metadata": { ... }
}
}
}
}
Get Font Tokens
GET /api/v3/fonts/tokens
Get font size token definitions.
Response:
{
"status": "success",
"data": {
"tokens": {
"xs": 6,
"sm": 8,
"md": 10,
"lg": 12,
"xl": 14,
"xxl": 16
}
}
}
Upload Font
POST /api/v3/fonts/upload
Upload a custom font file. It is saved as assets/fonts/<font_family><ext>.
Request: Multipart form data
font_file(required):.ttf,.otfor.bdf, max 10 MBfont_family(required): name for the font (letters, numbers,_,-)
Response (fields at the top level):
{
"status": "success",
"message": "Font custom_font uploaded successfully",
"font_family": "custom_font",
"filename": "custom_font.ttf",
"path": "assets/fonts/custom_font.ttf"
}
Delete Font
DELETE /api/v3/fonts/<font_family>
Delete an uploaded font (<font_family> is the file name without
extension). System fonts answer 403.
Font Preview
GET /api/v3/fonts/preview?font=<filename>&text=<sample>&size=12
Render text in a font, for the web UI font picker. BDF fonts are not
previewed (400).
Query Parameters:
font(required): font file name inassets/fonts/(e.g.press_start.ttf)text(optional): up to 100 characters (defaultSample Text 123)size(optional): 4-72 (default 12)bg,fg(optional): hex colours without#(default000000/ffffff)
Response:
{
"status": "success",
"data": {
"image": "data:image/png;base64,...",
"width": 140,
"height": 32
}
}
Font overrides (
/api/v3/fonts/overrides) were removed. Per-plugin font choices are made in each plugin's own settings.
Cache
List Cache Entries
GET /api/v3/cache/list
List cache files.
Response:
{
"status": "success",
"data": {
"cache_files": [ ... ],
"cache_dir": "/var/cache/ledmatrix",
"total_files": 12
}
}
Delete Cache Entry
POST /api/v3/cache/delete
Delete one cache entry by key. There is no clear-all option here; use
scripts/utils/clear_cache.py --clear-all on the Pi for that.
Request Body:
{
"key": "weather_current_12345"
}
WiFi
Get WiFi Status
GET /api/v3/wifi/status
Get current WiFi connection status.
Response:
{
"status": "success",
"data": {
"connected": true,
"ssid": "MyNetwork",
"ip_address": "192.168.1.100",
"signal": 70,
"ap_mode_active": false,
"auto_enable_ap_mode": true,
"last_connect_attempt": null
}
}
Scan WiFi Networks
GET /api/v3/wifi/scan
Scan for available WiFi networks. data is a list. If AP mode is active it is
turned off for the scan and back on afterwards, and message says so.
Response:
{
"status": "success",
"data": [
{
"ssid": "MyNetwork",
"signal": 70,
"security": "WPA2",
"frequency": 2437
}
]
}
Connect to WiFi
POST /api/v3/wifi/connect
Connect to a WiFi network.
Request Body:
{
"ssid": "MyNetwork",
"password": "mypassword"
}
Response: "status": "success" when connected; "status": "pending"
(with data.ssid) when the connection continues in the background — poll
/wifi/status and read last_connect_attempt. A wrong password answers
400 with "error_type": "wrong_password".
Disconnect from WiFi
POST /api/v3/wifi/disconnect
Disconnect from current WiFi network.
Enable Access Point Mode
POST /api/v3/wifi/ap/enable
Enable WiFi access point mode. Optional body {"force": true}.
Disable Access Point Mode
POST /api/v3/wifi/ap/disable
Disable WiFi access point mode.
Get Auto-Enable AP Setting
GET /api/v3/wifi/ap/auto-enable
Response:
{
"status": "success",
"data": {
"auto_enable_ap_mode": true
}
}
Set Auto-Enable AP
POST /api/v3/wifi/ap/auto-enable
Request Body:
{
"auto_enable_ap_mode": true
}
WiFi Radio
GET /api/v3/wifi/radio
Radio state: data.enabled (null if unknown), data.ethernet_connected,
data.available.
POST /api/v3/wifi/radio
Turn the WiFi radio on or off. Turning it off is refused unless Ethernet is
connected or force is true, so you don't cut off your own connection.
{
"enabled": false,
"force": false
}
Streams
Server-Sent Events, defined in web_interface/app.py. Each event is one
data: <json> line; idle connections get : heartbeat comments.
System Statistics Stream
GET /api/v3/stream/stats
data: {"timestamp": 1234567890.1, "uptime": "Running", "service_active": true, "cpu_percent": 25.5, "memory_used_percent": 45.2, "memory_available_mb": 1900.0, "cpu_temp": 45.0, "disk_used_percent": 60.0, "power": {...}}
Display Preview Stream
GET /api/v3/stream/display
data: {"timestamp": 1234567890.123, "width": 128, "height": 32, "image": "base64_data_here"}
Service Logs Stream
GET /api/v3/stream/logs
Each event carries the latest journal lines for ledmatrix and
ledmatrix-web as one text block:
data: {"timestamp": 1234567890.123, "logs": "2025-01-15T10:30:00+0000 host python[123]: ..."}
Logs
Get Logs
GET /api/v3/logs
The last 100 journal lines for ledmatrix.service and
ledmatrix-web.service, as one text block. Takes no parameters.
Response:
{
"status": "success",
"data": {
"logs": "2025-01-15T10:30:00+0000 host python[123]: Plugin loaded: football-scoreboard\n..."
}
}
Error tracking
Get Error Summary
GET /api/v3/errors/summary
Aggregated counts, detected patterns and recent errors across plugins and core components.
Get Plugin Errors
GET /api/v3/errors/plugin/<plugin_id>
Error health and statistics for one plugin.
Clear Errors
POST /api/v3/errors/clear
Clear error records older than max_age_hours (default 24, 1-8760).
Returns data.cleared_count.
{
"max_age_hours": 24
}
Health and Status
Health Check
GET /api/v3/health
Health of the web interface, display service, config file, plugin system and
display snapshot. data.status is healthy or degraded, with
data.services and data.checks.
Hardware Status
GET /api/v3/hardware/status
LED matrix initialization result written by the display service at startup.
Before the service has written it, data is
{"ok": null, "error": "Display service not yet started"}.
Sync Status
GET /api/v3/sync/status
Live multi-display sync status from the display process; before it has
written one, data is {"role", "port", "state": "starting"} from config.
Schedule (dim/power)
Get Dim Schedule
GET /api/v3/config/dim-schedule
Read the schedule that lowers brightness at configured times.
Response:
{
"status": "success",
"data": {
"enabled": true,
"dim_brightness": 30,
"mode": "per-day",
"days": {
"monday": { "enabled": true, "start_time": "20:00", "end_time": "07:00" },
"tuesday": { ... }
}
}
}
In global mode, start_time and end_time sit at the top level instead
of days.
Update Dim Schedule
POST /api/v3/config/dim-schedule
Replace the dim schedule. dim_brightness is 0-100 (default 30). In
per-day mode the days can be sent either as the days object that GET
returns, or as the web form's flat fields (monday_enabled,
monday_start, monday_end, ...). A day that is not sent counts as
enabled with default times 20:00-07:00; at least one day must be
enabled.
Integrations
MQTT Bridge
GET /api/v3/integrations/mqtt-bridge
Home Assistant MQTT bridge service state and settings: data.service,
data.config_exists, data.config_path, data.config (password
omitted), data.password_set, data.env_override_prefix.
PUT /api/v3/integrations/mqtt-bridge/config
Write integrations/mqtt_bridge/bridge_config.json. Only the keys you send
change. The password is write-only: omit mqtt_password to keep it, send a
value to replace it, or send "clear_password": true. A password with
mqtt_tls off is refused unless allow_insecure_mqtt is true. Returns
data.password_set and data.restart_required (the bridge must be
restarted to pick up changes). See
integrations/mqtt_bridge/README.md.
Plugin-specific endpoints
A handful of endpoints belong to individual plugins.
Calendar
GET /api/v3/plugins/calendar/list-calendars
List the calendars on the authenticated Google account. Used by the calendar
plugin's config UI. Returns calendars at the top level. The upload and
authenticate endpoints are under Plugins.
Of The Day
POST /api/v3/plugins/of-the-day/json/upload
Upload JSON data files (multipart field files) as Of-The-Day categories.
Returns uploaded_files and total_files at the top level.
POST /api/v3/plugins/of-the-day/json/delete
Delete an uploaded data file.
{
"file_id": "category_name"
}
Plugin Static Assets
GET /api/v3/plugins/<plugin_id>/static/<path:file_path>
Serve a static file from a plugin's directory. Used internally by the web UI to render plugin previews and icons.
Starlark Apps
The Starlark plugin lets you run Tronbyt Starlark apps on the matrix. These endpoints expose its UI.
Status
GET /api/v3/starlark/status
Returns whether the Pixlet binary is installed and the Starlark plugin is operational.
Install Pixlet
POST /api/v3/starlark/install-pixlet
Download and install the Pixlet binary on the Pi.
Apps
GET /api/v3/starlark/apps — list installed Starlark apps
GET /api/v3/starlark/apps/<app_id> — get app details
DELETE /api/v3/starlark/apps/<app_id> — uninstall an app
GET /api/v3/starlark/apps/<app_id>/config — get app config schema
PUT /api/v3/starlark/apps/<app_id>/config — update app config
POST /api/v3/starlark/apps/<app_id>/render — render app to a frame
POST /api/v3/starlark/apps/<app_id>/toggle — enable/disable app ({"enabled": bool}; omit to flip)
Repository (Tronbyt community apps)
GET /api/v3/starlark/repository/categories — list categories
GET /api/v3/starlark/repository/browse — every app with metadata (filtering happens client-side; cached for 2 hours)
POST /api/v3/starlark/repository/install — install an app: {"app_id": "...", "render_interval": 300, "display_duration": 15}
Upload custom app
POST /api/v3/starlark/upload
Upload a custom Starlark .star file as a new app. Multipart fields: file
(required, max 5 MB), name, app_id, render_interval,
display_duration.
Editor
A Pixlet editing session for one app. The display is stopped while a session runs.
GET /api/v3/starlark/editor/apps — apps the editor can open (data.apps, data.apps_dir, data.pixlet_available)
GET /api/v3/starlark/editor/status — data.running, plus app_id, port, pid, started_at, timeout, seconds_remaining, host_bound while running
POST /api/v3/starlark/editor/start — {"app_id": "...", "timeout": 1800, "port": 8080} (timeout and port optional)
POST /api/v3/starlark/editor/stop — end the session and restart the display
Skins
GET /api/v3/skins
Installed scoreboard skins (optional ?plugin_id= filter). Skins are not
supported by the current scoreboard plugins, so the response carries
data.supported: false and a data.message; clients must not offer these
as selectable. See SKIN_SYSTEM.md.
Error Responses
Errors use one of two shapes. Most endpoints answer:
{
"status": "error",
"message": "Error description",
"details": "Additional error details (optional)"
}
Endpoints built on the structured error helper add a code and category:
{
"status": "error",
"error_code": "CONFIG_SAVE_FAILED",
"error_category": "configuration",
"message": "Error description",
"details": "optional",
"context": { },
"suggested_fixes": [ ]
}
Common HTTP Status Codes:
200: Success400: Bad Request (invalid parameters)403: Forbidden (e.g. deleting a system font)404: Not Found (resource doesn't exist)408: Timed out (plugin actions, auth scripts)500: Internal Server Error503: Service Unavailable (feature not available)
See Also
- Plugin API Reference - API for plugin developers
- Plugin Development Guide - Complete plugin development guide
- Web Interface README - Web interface documentation