---
title: Litmus Unify
slug: api-docs/litmus-unify
description: REST and GraphQL API for Litmus Unify: 28 endpoints covering UNS topic management, MQTT broker control, security, integrations, and tooling for the industrial data fabric.
docTags: 
createdAt: 2026-05-11T22:01:40.049Z
---

# Litmus Unify (LUNS)

Litmus UNS is the Unified Namespace - an MQTT broker plus structured namespace plus account / ACL management plane. Edges publish here; downstream systems subscribe.

## GraphQL-only

LUNS exposes a **single endpoint** for all operations:

```javascript
POST {{uns_url}}/mqtt/gql
```

All 28 documented endpoints share this URL. The folder structure in the API portal (Dashboard / UNS / Security / MQTT / Integrations / Tools) is organizational - the actual operation is in the GraphQL query/mutation body.

:::BlockQuote
There is no REST surface for LUNS. If a tutorial tells you to call `POST /uns/account`, that's wrong - it's `POST /mqtt/gql` with a `createAccount` mutation in the body.
:::

## Module map (logical, not URL)

| Section      | Purpose                                         | Endpoints |
| ------------ | ----------------------------------------------- | --------- |
| Dashboard    | Broker stats, connected client counts           | 4         |
| UNS          | Namespace hierarchy, models, instances          | 7         |
| Security     | Accounts, ACL rules, tokens, LE activation      | 10        |
| MQTT         | Topic listing, retained messages, broker config | 4         |
| Integrations | Bridges to external brokers / cloud             | 2         |
| Tools        | Diagnostics, exports                            | 1         |

## Auth

OAuth2 password grant against the embedded Keycloak:

```javascript
POST {{uns_url}}/auth/realms/standalone/protocol/openid-connect/token
```

Form body: `grant_type=password`, `client_id`, `username`, `password`. The returned `access_token` is sent as `Authorization: Bearer <token>` on every `/mqtt/gql` call.

## First call

```bash
curl -sk -X POST "https://<uns-host>/mqtt/gql" \
  -H "Authorization: Bearer $UNS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"query":"query { account { id username acType enabled } }"}'
```

## Common operations

| Operation                  | GraphQL                                                   |
| -------------------------- | --------------------------------------------------------- |
| List accounts              | `query { account { ... } }`                               |
| Create account             | `mutation { createAccount(input: { ... }) { id } }`       |
| Add ACL rule               | `mutation { addAccountRules(input: { ... }) }`            |
| Enable account             | `mutation { enableAccount(input: { accountId: "..." }) }` |
| Create LE activation token | `mutation { createLitmusEdgeActivationToken(...) }`       |

See [Provision UNS MQTT Account](#) for the full create-account chain.
