API
Cloud backend at api.eyeban.ir versus the machine-local API on 127.0.0.1:17300.
Eyeban exposes two different API surfaces. Do not confuse the product cloud backend with a public third-party developer platform.
Cloud API (api.eyeban.ir)
The desktop workbench talks to api.eyeban.ir for:
- Authentication and session
- Agent runs over SSE
- Model routing and entitlements
- Account / wallet related state
This is the application backend. Undocumented cloud routes should be treated as internal. Do not build production integrations against reverse-engineered paths.
Local API (127.0.0.1:17300)
When enabled, the workbench ships a Local API bound to 127.0.0.1:17300 for same-machine tooling. Endpoint groups include:
- status — process / readiness style information
- tasks — local task listing
- files — workspace file operations
- search — search against the local index
- git — SCM helpers
- terminals — terminal session hooks
- agent — local agent control surface
- permissions — permission state
- tools — tool enumeration / invocation helpers exposed locally
The Local API is not exposed to the public internet by default. Do not port-forward it casually. Bind stays loopback for a reason.
Auth and safety
Local API calls assume a trusted user on the same machine. Cloud calls require a signed-in Eyeban account. Never paste session cookies into scripts you do not control.
Guidance
Prefer the workbench UI for everyday work. Use Local API for controlled local automation. Use cloud only through the signed-in client unless Eyeban publishes a separate stable public HTTP product later on this page.