AdGuard Home does not use an API key. Encode your AdGuard UI login as Base64 username:password
(Linux/macOS: echo -n 'admin:yourpass' | base64).
Configuration docs
Use the API token from Pi-hole Settings → API (or web password on older installs).
Copy the API key from Settings → General in the *arr app.
Copy the API key from the service settings (Overseerr/Jellyseerr → General).
API key from Prowlarr Settings → General. Hover the card to see indexers and queue.
Format: username|password for the NZBGet Web UI. Hover the card for queue and download speed.
Optional username|password if RPC auth is enabled. Leave empty on trusted LAN. Hover for torrent stats.
API key from SABnzbd Config → General.
API key from Jackett UI → API Key (or copy from dashboard).
API key from Tautulli Settings → Web Interface.
Long-lived API token from Audiobookshelf user settings.
API key from Immich Account → API Keys.
Tdarr URL only — no API key needed on most LAN installs. Use Tdarr server port (default 8265).
API key from Maintainerr Settings → API.
Optional JWT/API key if auth is enabled. Leave empty on trusted LAN.
Format: username|password for the qBittorrent Web UI. Enable Web UI in qBittorrent settings. Hover the card for download speed and active torrents.
API key from Bazarr Settings → General. Shows missing subtitles (hover card).
Use your public status page slug (Settings → Status Pages), or an Uptime Kuma API key for monitor count.
Format: account_id|tunnel_id|api_token — token needs Account → Cloudflare Tunnel → Read.
App URL can point to your tunnel hostname or Cloudflare dashboard.
Peanut/NUT base URL in the URL field. Leave credential empty if your instance has no API auth.
URL: https://fritz.box (or your box LAN IP). Credential: username|password for a FRITZ!Box user — use a dedicated limited account if possible. Enable Accept invalid certs in Settings if needed.
API access token from Portainer My account → Access tokens. URL is your Portainer instance (e.g. https://portainer:9443).
Format: api_key|api_secret from OPNsense System → Access → API Keys. Enable API on the firewall.
REST API key from pfSense (requires REST API package). URL is your pfSense host.
API key from TrueNAS Credentials → API Keys. Use the TrueNAS web URL (SCALE or CORE).
UniFi OS / Controller URL. Credential: username|password for a local admin account.
Service account or API key from Grafana Administration → Service accounts.
Leave as none if your instance has no auth on the LAN. Otherwise use a bearer token or password.
API token from Beszel hub Settings → API tokens.
API token from Paperless-ngx Settings → API.
Bearer token from Mealie user profile API tokens.
Format: username|app_password — create an app password in Nextcloud security settings.
ADMIN_TOKEN from your Vaultwarden environment. Used for admin user/org counts.
Deluge Web UI password (from Preferences → WebUI). Enable Web UI and JSON-RPC.
Subsonic API: username|password (or token password from Navidrome user settings).
API key from Komga User → API keys.
App password: username|password or a PhotoPrism app password token.
Format: user@pam!tokenid|secret — API token from Proxmox Datacenter → Permissions → API Tokens.
Tailscale OAuth/API key with devices:read. URL field is ignored (uses Tailscale API).
NetBird personal access token. URL is your NetBird dashboard/API host.
Ollama base URL (e.g. http://host:11434). No API key required for local installs.
Open WebUI URL. Optional API key from Settings → Account → API Keys (lists models); without key, health check only.
API key or credentials from the service settings. See docs for format hints per app.
Health-check integration: use none if no API auth. Keeps a 1×1 link card with online status.