Nexus Legacy API Notes

This folder documents the Nexus Legacy game API capabilities that are currently used or observed by this addon.

Scope

  • Coverage is based on endpoints referenced in the source tree.
  • Existing files document endpoints that were already analyzed earlier.
  • New files added here document the remaining observed capabilities.
  • Some payloads are fully confirmed from TypeScript models.
  • Some payloads are partial and marked as inferred when the addon only consumes a subset of fields.

Layout

  • get/ — read-only endpoints. Each file’s example is a real captured response.
  • post/ — mutating endpoints (POST, plus the one DELETE: post/ark_labs_detach.md). Their examples are request bodies; response shapes are marked inferred where they were not probed.
  • _sweeps/ — dated audit reports, not per-endpoint docs.

The index below stays grouped by game area, so the folder in each link tells you the method.

Confirmed Core Behavior

  • GETs go straight from the background service worker via apiGet(), authenticated with a Bearer token read from the game session cookie.
  • POSTs are routed through an open game tab instead (gamePost() → the content script’s GAME_FETCH handler, with a scripting fallback when no content script is live). A Bearer POST sent directly from the extension carries the extension’s Origin, which the server answers with a 500 — running the fetch in the page makes it same-origin, exactly like the game’s own call.
  • The tab is matched against the current universe’s host specifically, not a *.nexuslegacy.space wildcard, so a request never crosses universes when both are open.
  • Rate-limit headers ratelimit-limit, ratelimit-remaining, and ratelimit-reset are observed and used by the client.

Live Audit (Primary: S0)

Endpoint Index

Authentication and Player

Planet, Research, and Assets

Fleet and Exploration

Galaxy and Stations

Market and Trade

Logistics

Rankings and Notifications

Leadership

Artifacts

Ark and Ark Forge

Combat Simulator

Command Center