API

API paths, HTTP methods, and access requirements registered in the default template.

The default template registers its APIs centrally in src/api/routes.ts. Application endpoints use the /api prefix, and the built-in OAuth 2.0 service uses /oauth.

Common responses

src/types.ts defines APIResponse<T>. The tables below describe this type's contract. Not all application endpoints currently use the full structure. Some successful responses return only success and data, and the global exception handler may omit error. Use each endpoint's actual response structure rather than assuming that every response includes the fields marked as required below. Protocol endpoints such as the OAuth 2.0 token endpoint return their own OAuth 2.0-compliant response structures without this wrapper.

Successful responses

Prop

Type

Failed responses

Prop

Type

/api/auth

Authentication routes are registered in src/core/services/auth/const.ts and src/core/services/auth/routes.tsx.

MethodPathPurpose
POST/api/auth/logoutSign out of the current account
GET/api/auth/step-up/statusCheck step-up authentication status for sensitive operations
POST/api/auth/step-up/challengeStart step-up authentication
POST/api/auth/step-up/verifyComplete step-up authentication
POST/api/auth/loginSign in
POST/api/auth/login-modalSign in through a modal flow
POST/api/auth/google-one-tapHandle Google One Tap sign-in
POST/api/auth/signupCreate an account
POST/api/auth/verify-emailSubmit an email verification code
POST/api/auth/resend-emailResend an email verification code
POST/api/auth/setup-2faComplete two-factor authentication setup
POST/api/auth/verify-2faVerify a two-factor authentication code
POST/api/auth/verify-recovery-codeVerify a recovery code
POST/api/auth/forgot-passwordStart a password reset
POST/api/auth/reset-passwordSet a new password
POST/api/auth/reset-password/verify-emailVerify an email verification code during a password reset
POST/api/auth/reset-password/verify-2faVerify a two-factor authentication code during a password reset
POST/api/auth/reset-password/verify-recovery-codeVerify a recovery code during a password reset
GET/api/auth/oauth2/githubHandle the GitHub OAuth callback
GET/api/auth/oauth2/googleHandle the Google OAuth callback
GET/api/auth/current-userReturn the currently signed-in user

In production, the middlewares configuration in src/core/services/auth/const.ts loads request-blocking or rate-limiting middleware for endpoints such as sign-in, signup, verification codes, and password resets. Each authentication operation's configuration determines which middleware it uses.

/api/account

These endpoints let signed-in users manage their profile, security settings, products, payments, affiliate participation, and in-app notifications.

Profile and security

MethodPathPurpose
POST/api/account/profileUpdate profile information such as the user's name
GET/api/account/profile/email-verificationCheck verification status for an email address change
POST/api/account/profile/send-update-emailSend the verification code required to change an email address
POST/api/account/security/initiate-2faStart two-factor authentication setup
POST/api/account/security/enable-2faEnable two-factor authentication
POST/api/account/security/disable-2faDisable two-factor authentication
POST/api/account/security/regenerate-recovery-codesRegenerate recovery codes
GET/api/account/security/delete-accountRetrieve information required to delete the account
POST/api/account/security/delete-accountDelete the current account

Products, payments, and menus

MethodPathPurpose
GET/api/account/productsReturn product information visible to the current user
GET/api/account/paymentsReturn the current user's purchases and subscriptions
GET/api/account/menu-indicatorsReturn indicator counts for the account menu

Affiliate program

MethodPathPurpose
GET/api/account/affiliateReturn the current user's affiliate overview
GET/api/account/affiliate/commission-summaryReturn a commission summary
GET/api/account/affiliate/invalid-commissionsReturn commissions excluded from settlement
POST/api/account/affiliate/email-verificationVerify the email address to enable affiliate participation
POST/api/account/affiliate/enableEnable affiliate participation
GET/api/account/affiliate/payout-profileRead payout details
POST/api/account/affiliate/payout-profileSave payout details

In-app notifications

MethodPathPurpose
GET/api/account/notificationsReturn the current user's notifications
POST/api/account/notifications/readMark notifications as read
POST/api/account/notifications/:notificationId/openRecord that a notification was opened

Payments, support tickets, and newsletter subscriptions

MethodPathPurpose
POST/api/payments/checkout/:productId/:planIdCreate a checkout session
POST/api/payments/:provider/billingCreate a link to the payment provider's billing portal
POST/api/webhooks/:providerReceive payment provider webhooks
POST/api/ticketCreate a support ticket
GET/api/ticket/:keyRetrieve a support ticket by its access key
POST/api/ticket/:key/replyReply to a support ticket
POST/api/ticket/:key/closeClose a support ticket
POST/api/newsletter/subscriptionsSubscribe to the mailing list

Webhooks do not require a signed-in browser session, but they must pass signature verification for the corresponding payment provider. The available values for :provider depend on the payment providers enabled in config/payment.ts.

/api/analytics/collect

MethodPathPurpose
POST/api/analytics/collectReceive first-party analytics data

This route is registered only when analytics.enabled is true in config/deploy.ts. When analytics is disabled, requests to this path return 404.

/oauth

MethodPathPurpose
POST/oauth/tokenExchange an authorization code or refresh a token
POST/oauth/token/revokeRevoke a token
POST/oauth/authorize/consentApprove an authorization request
POST/oauth/authorize/dismissDeny an authorization request
GET/oauth/current-userReturn the user information used by the current OAuth authorization page

These endpoints belong to the default template's built-in OAuth 2.0 service. OAuth clients, authorization codes, and tokens are stored in oauth_client, oauth_auth_code, and oauth_token, respectively.

/api/dashboard

The entire dashboard route group first runs the requireDashboardAdmin check. Users who do not pass this administrator check cannot access the endpoints below.

Users, roles, and entitlements

Path prefixSupported operations
/api/dashboard/usersList, search, and view users, disable or enable users, soft-delete users, and revoke sessions
/api/dashboard/rolesList, create, enable, disable, and revoke roles
/api/dashboard/entitlementsList, create, adjust, enable, and disable entitlements, and refresh subscription cycles
/api/dashboard/entitlement-eventsQuery entitlement quota events

Payments and OAuth clients

Path prefixSupported operations
/api/dashboard/payments/subscriptionsList subscriptions and view subscription details
/api/dashboard/payments/purchasesList one-time purchases and view purchase details
/api/dashboard/oauth-clientsList, create, edit, enable, disable, and delete OAuth clients, and regenerate client secrets

Reaction, support tickets, and logs

Path prefixSupported operations
/api/dashboard/reaction/eventsList Event executions and view execution details
/api/dashboard/reaction/commandsList Command executions, view execution details, and retry manually
/api/dashboard/ticketsSupport ticket lists, details, replies, message editing, hiding, unhiding, and status updates
/api/dashboard/logger/systemQuery system logs
/api/dashboard/logger/auditQuery audit logs
/api/dashboard/logger/alertQuery alert logs

Statistics and affiliate program

Path prefixSupported operations
/api/dashboard/statsDashboard statistics for users, subscriptions, support tickets, Reaction executions, and logs
/api/dashboard/analyticsTraffic overview, events, sessions, performance, funnels, filter options, and client IP addresses
/api/dashboard/affiliates/usersList affiliates, view details and commissions, and disable or restore affiliates
/api/dashboard/affiliates/payoutsList monthly settlements, view overviews, commissions, and payout records, and recalculate summaries

Dashboard analytics queries and frontend data collection share the analytics.enabled switch. When analytics is disabled, query endpoints under /api/dashboard/analytics are not registered.

Notifications

Path prefixSupported operations
/api/dashboard/notificationsList and create notifications, view details, and update status

Source locations

ContentLocation
Main API entry pointsrc/api/routes.ts
Authentication actions and pathssrc/core/services/auth/const.ts, src/core/services/auth/routes.tsx
Account endpointssrc/api/account/
Dashboard endpointssrc/api/dashboard/
Payment endpointssrc/api/payments/
OAuth 2.0 servicesrc/api/oauth2-server/
Request parameter validationschema.ts or route files in each endpoint directory