TabGeckoDocs
Website
Documentation / Downloads and CLI

Downloads and CLI

Versioned source snapshots served directly by this documentation site. No private repository login is needed and no token values are included.

Download files

OpenAPI 3.1 · native API reference

openapi.json

SHA-256c571499643bffe7b465e66011652639661dd46bc39196a86f285a347f360407e

Postman collection · native API + MCP

tabgecko.postman_collection.json

SHA-2566a4d47fe79a5c7c449b9bbf31daa3a27c71ba9b55c9ccaef50194497fb7cf91d

Postman environment · empty credentials

tabgecko.postman_environment.json

SHA-25607f1db531d4a55f038107608609832f62ae01ad0777b4b38c7f378c6df7bb2c0

Node.js CLI and stdio bridge

tabgecko.mjs

SHA-2566861520219202dfd86eaaa77cbac065751e45b10ab515bb075eadc16c4b344a9

Skill instructions · Markdown

tabgecko-skill.md

SHA-256e448f389666785783fde0c4adf819944bf23e1ff22e0585d4cf2a97e24f8792f

Download manifest and checksums

CLI usage

Node.js 22+
node tabgecko.mjs help
node tabgecko.mjs status
node tabgecko.mjs profiles --limit 25
node tabgecko.mjs profiles --limit 25 --cursor "NEXT_CURSOR"
node tabgecko.mjs request GET /api/v1/groups
node tabgecko.mjs request POST /api/v1/profiles profile.json

Configure ADBR_API_TOKEN locally and ADBR_API_URL to the displayed loopback address. REST commands print successful JSON to stdout and errors to stderr; exit codes are 0 and 1. request expects a filename for a UTF-8 JSON body, not inline JSON; a UTF-8 BOM is accepted. GET must omit the body filename. Quote shell paths and query strings that contain spaces or ampersands.

ADBR_API_TIMEOUT_MS sets the REST deadline including the response body: 1–300000 ms, default 30000. It does not configure MCP. The CLI rejects redirects and non-loopback HTTP destinations and never retries mutations automatically. Runtime discovery can use ADBR_BOOTSTRAP_DIR; the CLI does not read the app’s session-token file.

Import into Postman

  • Import the collection and environment JSON. Select the imported environment and set baseUrl to the app address.
  • Set bearerToken and mcpToken only in your private local environment values. Do not sync or export filled credentials.
  • Begin with GET /status, then a scoped read request. Optional query fields are disabled. Replace path IDs and review generated payloads; schema-derived examples are not production-ready data.
  • Requests outside a conservative read allowlist need allowRequestOnce set to the exact METHOD /template/path shown in the request’s pre-request script. That permission is consumed once. The guard requires a local URL, the expected route and suitable token configuration.
  • Use a current Postman version with pm.execution.skipRequest. Do not run the entire collection blindly. No automatic chained requests or response-to-variable credential capture is included. Redirect following is disabled.

Use the Skill file

The downloadable Markdown file is an instruction document for clients that support skills. Review it, then install it using your client’s supported mechanism, commonly as SKILL.md in a skill directory. It is not a browser extension or installer and grants no rights by itself. Put the companion CLI beside it when using the CLI fallback; configure a separate minimal local token.

Integrity and regeneration

The manifest contains SHA-256 hashes for the published files and their source snapshots. Compare hashes after downloading. Maintainers regenerate from an app checkout with scripts/sync-api-docs.mjs and then run the site build. Builds use the committed sanitized snapshot and require no access to a private repository.