Enabling the REST API
By default, running a Rasa server does not enable the API endpoints. Interactions with the bot can happen over the exposedwebhooks/<channel>/webhook endpoints.
To enable the API for direct interaction with conversation trackers and other
bot endpoints, add the --enable-api parameter to your run command:
SANIC_WORKERS=1). You can change the number
of worker processes using the SANIC_WORKERS environment variable. It is
recommended that you set the number of workers to the number of available CPU cores
(check out the
Sanic docs
for more details). This will only work in combination with the
RedisLockStore (see Lock Stores).
As of Rasa Pro 3.19, the server runs on Sanic 25, which spawns each worker as a
separate process and rebuilds the application within it. This has two
user-visible effects when SANIC_WORKERS is greater than 1:
GET /statusincludes aworker_pidfield that reports the process ID of the worker that handled the request.PUT /modelandDELETE /modelonly affect the worker that handles the request. SetSANIC_WORKERS=1when loading or unloading models at runtime.
Security Considerations
We recommend that you don’t expose the Rasa Server to the outside world directly, but rather connect to it via e.g. Nginx. Nevertheless, there are two authentication methods built in:Token Based Auth
To use a plaintext token to secure your server, specify the token in the argument--auth-token thisismysecret when starting
the server:
AUTH_TOKEN to set the auth token:
JWT Based Auth
To use JWT based authentication, specify the JWT secret in the argument--jwt-secret thisismysecret
on startup of the server:
JWT_SECRET to set the JWT secret:
--jwt-private-key
CLI argument. You must pass the public key to the --jwt-secret argument, and also specify the algorithm to the
--jwt-method argument:
Authorization header that is signed using this secret
and the HS256 algorithm e.g.
user key,
which in turn must contain the username and role attributes.
The following is an example payload for a JWT token:
role is admin, all endpoints are accessible.
If the role is user, endpoints with a sender_id parameter are only accessible
if the sender_id matches the payload’s username property.
For the user trackers endpoint (GET /users/{user_id}/trackers), you should use user_id instead of username in the payload.
In this case, the path user_id parameter is matched against the payload’s username property. For example: