Under Admin Panel → Plugins → API Endpoints → Configure you'll find the following settings:
| Setting | Description | Default |
|---|---|---|
| Enable API Endpoints | Globally enables/disables all extended endpoints. Access per endpoint is additionally controlled via API key permissions. | enabled |
| Require Markdown Plugin | When enabled, the API rejects ticket creation with format=markdown if the Markdown Support plugin is not active. When disabled, the request is processed as html instead. |
disabled (lenient) |
| Installed Version | Informational only, auto-managed by the plugin (auto-update tracking) — do not edit manually. | automatic |
The plugin extends osTicket's API key permission system with granular permissions.
| Permission | Database Field | Grants Access To |
|---|---|---|
| Create Tickets | can_create_tickets |
POST /tickets |
| Read Tickets | can_read_tickets |
GET /tickets/:number, GET /tickets-attachment-download/:file_id |
| Update Tickets | can_update_tickets |
PATCH /tickets/:number |
| Search Tickets | can_search_tickets |
GET /tickets/search |
| Delete Tickets | can_delete_tickets |
DELETE /tickets/:number |
| Read Statistics | can_read_stats |
GET /tickets-stats, GET /tickets-statuses |
| Manage Subtickets | can_manage_subtickets |
All subticket endpoints (requires Subticket Manager Plugin) |
The exact endpoint-to-permission mapping is in the API Documentation.
The plugin supports legacy API keys (without the new permission columns):
can_create_tickets → falls back to canCreateTickets() (osTicket standard behavior)can_read_tickets → falls back to canCreateTickets() (read treated like create)can_update_tickets → falls back to canCreateTickets()Migrate older API keys to the new permissions to get granular control — without migration they keep working unchanged.
can_read_statscan_create_ticketsTip:
can_delete_ticketsis disabled by default. Consider aPATCHto status "Closed"/"Archived" instead of permanently deleting tickets.