Mobile and Comfy Portal¶
This page covers integrating mobile apps and Comfy Portal with a ComfyUI instance that runs MSS-Login.
Comfy Portal (iOS / Android)¶
Comfy Portal uses standard ComfyUI APIs:
POST /prompt— run workflowsGET /queue,GET /history— status and resultsGET /view— output images- WebSocket
/ws— live updates - Userdata workflow APIs for sync
MSS-Login does not require a proprietary Portal protocol. Configure Portal with your server URL and authenticate the same way as any API client.
Recommended auth for Portal¶
- In ComfyUI (browser), log in as the user.
- Generate a long-lived API token via Settings → mss-login → Generate Token, or:
POST /mss-login/generate_token
- Configure Portal to send
Authorization: Bearer <token>(or the token mechanism Portal supports).
Ensure the user's role has can_run and can_access_api. Remote clients (including cellular / non-LAN IPs) must send a valid token; the remote API guard allows /api/cpe/* only when the token is present and valid.
Per-user workflow list (CPE paths)¶
Comfy Portal calls comfy-portal-endpoint paths such as GET /api/cpe/workflow/list. MSS-Login intercepts those routes and serves that user's stored workflows (plus any shared/global JSON files), using the same response shape as CPE:
| Method | Path | Body / query | Notes |
|---|---|---|---|
| GET | /cpe/workflow/list and /api/cpe/workflow/list |
— | { "status": "success", "workflows": [ { "filename", "size", "modified" } ] } |
| GET | /cpe/workflow/get |
?filename= |
{ "status": "success", "filename", "workflow": "<raw JSON string>" } |
| POST | /cpe/workflow/save |
{ "workflow": "<json string>", "name": "optional.json" } |
Writes into the authenticated user's workflow dir |
| GET | /cpe/workflow/get-and-convert |
?filename= |
Returns API-format graphs; UI-format graphs need CPE's headless browser (503 otherwise) |
| GET | /cpe/health |
— | { "status": "success", "browser": { "status": "ready" } } |
POST /cpe/workflow/convert is left to comfy-portal-endpoint when that extension is installed.
Saving through CPE requires can_modify_workflows (defaults to allowed for every role except guest).
comfy-portal-endpoint¶
The comfy-portal-endpoint service provides workflow list/get/save/convert using a headless browser that loads the real ComfyUI frontend.
Implications for MSS-Login:
- A login wall that prevents the ComfyUI UI from loading breaks workflow conversion.
- If you enable strict auth, allow unauthenticated access to minimal frontend assets required for conversion, or run conversion on an internal network without the login intercept.
- Document for users that full auth + loading-page flows may disable Portal workflow sync.
Smooth auth for your own mobile app¶
For a custom mobile client, prefer this flow:
- One-time:
POST /mss-login/generate_token→ store token securely. - Every request:
Authorization: Bearer <token>. - WebSocket:
wss://host/ws?token=<token>. - Validate once:
GET /mss-login/api/mefor permissions. - Run pipelines per Image generation pipeline.
Avoid scraping HTML login pages or cookies unless you control a WebView session.
Troubleshooting¶
| Symptom | Likely cause |
|---|---|
401 on /prompt from mobile network |
Missing token, or REQUIRE_AUTH_FOR_REMOTE_API=true without Bearer auth |
401 on /prompt with token |
Revoked token, wrong server, or clock skew on JWT sessions |
403 on /prompt |
can_run false for role |
403 MODEL_NOT_ALLOWED |
Workflow references models user cannot access |
403 on /view |
NSFW policy blocked output |
| Portal cannot sync workflows | Frontend blocked by auth; see comfy-portal-endpoint section |
401 on /api/cpe/workflow/list |
Missing/invalid token, or remote API guard (non-LAN IP without Bearer) |
| Empty workflow list in Portal | No JSON files in that user's data-dir workflow folder yet; save one or copy into Users/<name>/workflows/ |
HTML redirect to /login instead of JSON |
Client sent Accept: text/html; use Bearer header and expect JSON 401 |
Debug tips¶
- Confirm HTTPS and correct
HOST_BASE_URLif links or redirects fail. - Test with
curl -H "Authorization: Bearer …" https://host/mss-login/api/me. - Check server logs under the MSS-Login data directory.