{"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"configure-the-try-it-api-console","__idx":0},"children":["Configure the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Try it"]}," API console"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"overview","__idx":1},"children":["Overview"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Try it"]}," console allows your users to make API calls directly from the API docs."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/content-assets/console-screenshot-992f3861a9c734e5.png","alt":"Redocly Reference page with the Try it console"},"children":[]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Try it"]}," feature is not available in Redoc. You need access to Redocly API docs or Developer portal products to use the Try it feature."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"requirements","__idx":2},"children":["Requirements"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In order to implement the ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Try it"]}," feature (either for API docs or within the Developer portal), you must configure security schemes and servers in your OpenAPI definition. Your server must also support CORS requests (or you can use our CORS proxy)."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"security-schemes-and-authentication","__idx":3},"children":["Security schemes and authentication"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Try it"]}," console supports the security schemes that are ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://github.com/OAI/OpenAPI-Specification/blob/master/versions/3.0.3.md#security-scheme-object"},"children":["supported by OpenAPI 3.0 and 3.1"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This section lists the authentication configurations supported for each security schema in the ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Try it"]}," console."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Legend"},"children":["Legend"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["✔️: full support"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["⚠️: partial support"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["❌: unsupported"]}]}]}]}]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Type"},"children":["Type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Variation"},"children":["Variation"]},{"$$mdtype":"Tag","name":"th","attributes":{"align":"center","data-label":"Status"},"children":["Status"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Notes"},"children":["Notes"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["apiKey"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["cookie"]},{"$$mdtype":"Tag","name":"td","attributes":{"align":"center"},"children":["✔️"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["apiKey"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["header"]},{"$$mdtype":"Tag","name":"td","attributes":{"align":"center"},"children":["✔️"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["apiKey"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["query"]},{"$$mdtype":"Tag","name":"td","attributes":{"align":"center"},"children":["✔️"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["http"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["basic"]},{"$$mdtype":"Tag","name":"td","attributes":{"align":"center"},"children":["✔️"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["http"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["bearer"]},{"$$mdtype":"Tag","name":"td","attributes":{"align":"center"},"children":["✔️"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["oauth2"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["implicit"]},{"$$mdtype":"Tag","name":"td","attributes":{"align":"center"},"children":["✔️"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Add our callback URL to your app."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["oauth2"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["clientCredentials"]},{"$$mdtype":"Tag","name":"td","attributes":{"align":"center"},"children":["✔️"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Add our callback URL to your app."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["oauth2"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["password"]},{"$$mdtype":"Tag","name":"td","attributes":{"align":"center"},"children":["⚠️"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Enter access token in form."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["oauth2"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["authorizationCode"]},{"$$mdtype":"Tag","name":"td","attributes":{"align":"center"},"children":["✔️"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Add our callback URL to your app. This flow supports Proof Key for Code Exchange (PKCE) through the custom property ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["x-usePkce"]}," in the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["authorizationCode OAuth Flow Object"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["openIdConnect"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["token"]},{"$$mdtype":"Tag","name":"td","attributes":{"align":"center"},"children":["✔️"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Add our callback URL to your app. This flow maps to the oauth2 implicit flow. Supported by most identity providers. Hint: find the values your provider supports inside of the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["response_types_supported"]}," at the discovery URL."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["openIdConnect"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["code"]},{"$$mdtype":"Tag","name":"td","attributes":{"align":"center"},"children":["✔️"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Add our callback URL to your app. This flow maps to the oauth2 authorizationCode flow. Supported by most identity providers. Hint: find the values your provider supports inside of the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["response_types_supported"]}," at the discovery URL."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["openIdConnect"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["id_token"]},{"$$mdtype":"Tag","name":"td","attributes":{"align":"center"},"children":["❌"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["User message: \"Unsupported flow\"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["openIdConnect"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["id_token token"]},{"$$mdtype":"Tag","name":"td","attributes":{"align":"center"},"children":["❌"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["User message: \"Unsupported flow\"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["openIdConnect"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["code id_token"]},{"$$mdtype":"Tag","name":"td","attributes":{"align":"center"},"children":["❌"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["User message: \"Unsupported flow\"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["openIdConnect"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["code token"]},{"$$mdtype":"Tag","name":"td","attributes":{"align":"center"},"children":["❌"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["User message: \"Unsupported flow\"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["openIdConnect"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["code id_token token"]},{"$$mdtype":"Tag","name":"td","attributes":{"align":"center"},"children":["❌"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["User message: \"Unsupported flow\"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["openIdConnect"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["none"]},{"$$mdtype":"Tag","name":"td","attributes":{"align":"center"},"children":["❌"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["User message: \"Unsupported flow\"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["mutualTLS"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["-"]},{"$$mdtype":"Tag","name":"td","attributes":{"align":"center"},"children":["❌"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["User message: \"Unsupported flow\" (this was added in OpenAPI 3.1)."]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Try it"]}," authentication only works for your active browser session. When users enter their credentials, these are saved in the session storage and removed after the session ends. If you open a new session, users need to provide their authentication details to access the ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Try it"]}," feature."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Depending on the authentication scheme, Redocly displays the following:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["http basic"]}," - Username and password inputs"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["http bearer"]}," - Input for the auth token"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["apiKey"]}," - Input for the API Key"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["oauth2"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["implicit"]}," - Inputs for ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["client_id"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["scopes"]}," and Authorize button which redirects user to an identity provider:"," ",{"$$mdtype":"Tag","name":"Image","attributes":{"src":"https://user-images.githubusercontent.com/3975738/104177568-a8512700-5411-11eb-884c-e557aafdf701.png","alt":"Try it console with implicit flow"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["clientCredentials"]}," - Inputs for ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["client_id"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["client_secret"]}," and Request Token button:"," ",{"$$mdtype":"Tag","name":"Image","attributes":{"src":"https://user-images.githubusercontent.com/3975738/104177652-ca4aa980-5411-11eb-8b99-bb68a96fdb07.png","alt":"Try it console with client credentials flow"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["authorizationCode"]}," - Input for the access token directly."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["password"]}," - Input for the access token directly."]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["openIdConnect"]}," - OAuth2 implicit flow UI (it works only for OpenID servers that support the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["token"]}," ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["response_type"]},"). Redocly will support ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["code"]}," once we add support for ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["authorizationCode"]}," oauth2 flow."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"servers","__idx":4},"children":["Servers"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["OpenAPI 3 allows you to ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://github.com/OAI/OpenAPI-Specification/blob/master/versions/3.0.3.md#serverObject"},"children":["define the servers"]},", including optional ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://github.com/OAI/OpenAPI-Specification/blob/master/versions/3.0.3.md#server-variable-object"},"children":["server variable objects"]},"."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Property"},"children":["Property"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Required for Try it"},"children":["Required for Try it"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["url"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Yes"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["API requests are sent to this URL directly from the browser or via the CORS proxy."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["description"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["-"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["If provided, the description is displayed with the URL."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["variables"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["-"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["If provided, fields are added to supply values for each server variable defined."]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"request-handling","__idx":5},"children":["Request handling"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You can use one of these options to handle requests:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Directly from the browser (server requires CORS configuration)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["With a CORS proxy (server does not require CORS configuration)"]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"directly-from-the-browser","__idx":6},"children":["Directly from the browser"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The CORS ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS"},"children":["(Cross-Origin Resource Sharing)"]}," protocol allows scripts running in a browser to access resources from a different origin (e.g. a different domain or port). Preventing scripts from accessing external resources is a reasonable security policy."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["However in some cases, scripts must be able to access cross-origin resources to successfully complete a request, for example the ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Try it"]}," API console. For users to interact with your APIs through the API console, you must configure your server(s) to accept requests from a URL where your API reference docs are hosted."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Your server(s) must allow cross-origin resource sharing, and respond to the OPTIONS requests sent by the browser when the user works with the API console. The ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Access-Control-Allow-Origin"]}," header configured on the server tells the browser whether any origins are allowed to access a resource."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"with-a-cors-proxy","__idx":7},"children":["With a CORS proxy"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If you cannot configure your server(s) to allow CORS, you can use Redocly's ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["CORS Proxy"]}," feature to prevent issues with unsuccessful requests from the API console. When you enable the CORS Proxy feature, all requests sent from the API console are routed through the CORS proxy server. The URL in each request is automatically prepended by the CORS proxy URL."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The URL of the Redocly CORS proxy server is ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://cors.redoc.ly"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Customers who host Redocly products on-premises can use their own CORS proxy server, by setting the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["corsProxyUrl"]}," value to their own CORS proxy server URL in the Redocly configuration file."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Authentication-related URLs are not proxied. You can prepend our CORS proxy URL to your ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["authorizationUrl"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["tokenUrl"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["refreshUrl"]}," or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["openIdConnectUrl"]}," if required."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In Redocly Workflows, the CORS Proxy feature is enabled by default in projects created after March 2021, and disabled in pre-existing projects."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You can configure CORS Proxy for the following products:"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["API docs"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs-legacy/api-reference-docs/configuration/functionality"},"children":["in configuration file"]},": Modify the value of the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["corsProxyUrl"]}," option in the Redocly configuration file. The value can be the Redocly CORS proxy URL (https://cors.redoc.ly) or the URL of a custom CORS proxy server. To disable the CORS proxy, set ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["corsProxyUrl: false"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs-legacy/workflows/docs/#docs-settings"},"children":["in Redocly Workflows"]},": Navigate to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["API version > Settings > Features"]}," and (de)select the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Disable CORS Proxy"]}," checkbox in the ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Try it settings"]}," section."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Portals"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs-legacy/developer-portal/guides/reference-docs-integration"},"children":["in configuration file"]},": Modify the value of the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["settings: corsProxyUrl"]}," option in the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":[".page.yaml"]}," configuration file. Set the value to either the Redocly CORS proxy URL (https://cors.redoc.ly) or the URL of a custom CORS proxy server."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"em","attributes":{},"children":["To maximize the security and privacy of our clients and their users, Redocly does not collect or store any logs of traffic routed through the CORS proxy server."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["About Redocly's CORS Proxy"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The CORS proxy server is hosted on Heroku, and as a result, its IP addresses are highly dynamic. For more information, refer to the official AWS documentation for ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://docs.aws.amazon.com/general/latest/gr/aws-ip-ranges.html"},"children":["currently published IP ranges"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["We do not recommend adding entire IP ranges to your allowlist."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"enable-the-file-upload-helper","__idx":8},"children":["Enable the file upload helper"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Starting with version ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["2.1.12"]}," of Redocly API docs, the ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Try it"]}," console supports the file upload helper, making it easier to add files to a request. This feature is supported for OpenAPI 3.0 and OpenAPI 3.1."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["requestBody"]}," schema in the API definition must have valid properties according to the ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://github.com/OAI/OpenAPI-Specification/blob/main/versions/3.0.3.md#considerations-for-file-uploads"},"children":["OAS 3.0"]}," and ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://github.com/OAI/OpenAPI-Specification/blob/main/versions/3.1.0.md#considerations-for-file-uploads"},"children":["OAS 3.1"]}," specification, respectively."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["When the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["requestBody"]}," schema in the API definition is recognized as valid, the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Choose file"]}," button is visible in the request body section of the ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Try it"]}," console. Select the button to open the file picker dialog and add one or more files to your request."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/content-assets/console-file-upload-6c0af4b974b0dcb5.png","alt":"Try it console with the Choose file button visible"},"children":[]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The following examples illustrate different types of request body schemas that can be used with the file upload helper."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Examples for multipart/form-data"]}]},{"$$mdtype":"Tag","name":"Tabs","attributes":{"size":"medium"},"children":[{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"OpenAPI 3.0","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","header":{"controls":{"copy":{}}},"source":"requestBody:\n  content:\n    multipart/form-data:\n      schema:\n        type: object\n        properties:\n          fileBase64:\n            description: file to upload\n            type: array\n            items:\n              type: string\n              format: binary\n          fileBinary:\n            description: file to upload\n            type: array\n            items:\n              type: string\n              format: binary\n","lang":"yaml"},"children":[]}]},{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"LOpenAPI 3.1","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","header":{"controls":{"copy":{}}},"source":"requestBody:\n  description: Example description\n  required: true\n  content:\n    multipart/form-data:\n      schema:\n        type: object\n        properties:\n          fileBase64:\n            description: Example description\n            type: array\n            items:\n              type: string\n              format: base64\n          fileBinary:\n            description: Example description\n            type: array\n            items:\n              type: string\n              contentMediaType: application/octet-stream\n","lang":"yaml"},"children":[]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Examples for application/octet-stream"]}]},{"$$mdtype":"Tag","name":"Tabs","attributes":{"size":"medium"},"children":[{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"OpenAPI 3.0","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","header":{"controls":{"copy":{}}},"source":"requestBody:\n  content:\n    application/octet-stream:\n      schema:\n        type: string\n        format: base64\n","lang":"yaml"},"children":[]}]},{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"LOpenAPI 3.1","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","header":{"controls":{"copy":{}}},"source":"requestBody:\n  description: Example description\n  required: true\n  content:\n    application/octet-stream: {}\n","lang":"yaml"},"children":[]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Examples for binary image file (JPG, PNG)"]}]},{"$$mdtype":"Tag","name":"Tabs","attributes":{"size":"medium"},"children":[{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"OpenAPI 3.0","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","header":{"controls":{"copy":{}}},"source":"requestBody:\n  content:\n    'image/jpeg':\n      schema:\n        type: string\n        format: binary\n    'image/png':\n      schema:\n        type: string\n        format: base64\n","lang":"yaml"},"children":[]}]},{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"LOpenAPI 3.1","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","header":{"controls":{"copy":{}}},"source":"requestBody:\n  description: Example description\n  required: true\n  content:\n    'image/jpeg': {}\n    'image/png':\n      schema:\n        type: string\n        contentEncoding: base64\n","lang":"yaml"},"children":[]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"disable-the-try-it-console","__idx":9},"children":["Disable the ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Try it"]}," console"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To disable the ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Try it"]}," panel, set the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["hideTryItPanel"]}," to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["true"]},"."]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","header":{"controls":{"copy":{}}},"source":"theme:\n  openapi:\n    hideTryItPanel: true # Disable the _Try it_ console.\n","lang":"yaml"},"children":[]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"Tip"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You can also use the Redocly configuration file to set other feature options. Learn more about ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs-legacy/api-reference-docs/configuration/functionality"},"children":["docs-related configuration options"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Keep the configuration file in the root of your repository with your OpenAPI definitions, or upload it to Workflows with your OpenAPI definitions."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To disable the ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Try it"]}," panel for a single operation, use the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["x-hideTryItPanel"]}," specification extension. Set it to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["true"]}," on the operation level in your OpenAPI definition:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","header":{"controls":{"copy":{}}},"source":"openapi: '3.0.3'\ninfo: ...\ntags: [...]\npaths:\n  /example:\n    get:\n      summary: Example summary\n      description: Example description\n      operationId: examplePath\n      responses: [...]\n      parameters: [...]\n      x-hideTryItPanel: true\n","lang":"yaml"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"how-is-the-console-implemented","__idx":10},"children":["How is the console implemented?"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The *Try it** console is implemented as a ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["lazy-loadable standalone plugin"]},", so it does not increase the initial loading time."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The console plugin is loaded ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["on demand"]}," when a user clicks the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Try it"]}," button."]}]},"frontmatter":{"excludeFromSearch":true,"seo":{"title":"Configure the Try it console"}},"tagList":["admonition","tab","tabs"],"title":"Configure the Try it console","lastModified":"2025-08-10T02:58:02.000Z"}