Skip to content

API Connection Settings

Modern 3D printing workflows have evolved from manual SD card swapping to fully integrated network deployments.

Introduction & Architecture

Modern 3D printing workflows have evolved from manual SD card swapping to fully integrated network deployments. OrcaSlicer interfaces directly with remote print hosts (such as Klipper/Moonraker, OctoPrint, Repetier-Server, and Duet/RepRapFirmware) using structured Application Programming Interfaces (APIs).

When a user initiates a "Send G-code" or "Print" command, OrcaSlicer acts as a client requesting resources from the print host server. This relationship requires stable network bindings, cryptographic authentication, and robust protocol handshake mechanisms. Understanding how these layers interact prevents connection dropouts, file corruption, and security vulnerabilities on the shop floor.

graph TD
    OrcaSlicer[OrcaSlicer Client] -->|HTTP POST / API Key| WebAPI[Host REST API]
    OrcaSlicer -->|WebSocket Connection| WSStream[Real-time Telemetry]
    WebAPI -->|Save G-Code| HostStorage[Local Storage / SD Card]
    WSStream -->|State Updates| UI[Device Tab UI]

Theoretical Background & Protocols

Print Host Security & API Authentication Tokens

Exposing a 3D printer to a network without security controls is a severe risk. Heating elements, high-voltage stepper motors, and mechanical axes can be hijacked. Therefore, print hosts employ authentication mechanisms:

  • API Keys (Token-Based Authentication): A static, cryptographically generated alphanumeric string (typically 32 characters) passed in the HTTP request headers (e.g., X-Api-Key or Authorization: Bearer <Token>). This token serves as both identification and authorization, bypassing the need for a username and password.
  • JSON Web Tokens (JWT): Used dynamically by newer print hosts (like Moonraker). Upon initial login with username/password, the server issues a signed token which the client must present for subsequent API calls.
  • Basic Access Authentication: An legacy standard where credentials are sent as base64-encoded text in the header (Authorization: Basic <credentials>). This is highly insecure unless wrapped in a TLS/SSL layer.

Network Sockets & Communication Protocols

The integration operates on two concurrent channels:

CategoryOrcaSlicer
LibraryCAM library

Engineer, author of The Big Book of 3D Printing and additive manufacturing expert