API
API paths, HTTP methods, and access requirements registered in the default template.
The default template registers its APIs centrally in src/api/routes.ts. Application endpoints use the /api prefix, and the built-in OAuth 2.0 service uses /oauth.
Common responses
src/types.ts defines APIResponse<T>. The tables below describe this type's contract. Not all application endpoints currently use the full structure. Some successful responses return only success and data, and the global exception handler may omit error. Use each endpoint's actual response structure rather than assuming that every response includes the fields marked as required below. Protocol endpoints such as the OAuth 2.0 token endpoint return their own OAuth 2.0-compliant response structures without this wrapper.
Successful responses
Prop
Type
Failed responses
Prop
Type
/api/auth
Authentication routes are registered in src/core/services/auth/const.ts and src/core/services/auth/routes.tsx.
| Method | Path | Purpose |
|---|---|---|
POST | /api/auth/logout | Sign out of the current account |
GET | /api/auth/step-up/status | Check step-up authentication status for sensitive operations |
POST | /api/auth/step-up/challenge | Start step-up authentication |
POST | /api/auth/step-up/verify | Complete step-up authentication |
POST | /api/auth/login | Sign in |
POST | /api/auth/login-modal | Sign in through a modal flow |
POST | /api/auth/google-one-tap | Handle Google One Tap sign-in |
POST | /api/auth/signup | Create an account |
POST | /api/auth/verify-email | Submit an email verification code |
POST | /api/auth/resend-email | Resend an email verification code |
POST | /api/auth/setup-2fa | Complete two-factor authentication setup |
POST | /api/auth/verify-2fa | Verify a two-factor authentication code |
POST | /api/auth/verify-recovery-code | Verify a recovery code |
POST | /api/auth/forgot-password | Start a password reset |
POST | /api/auth/reset-password | Set a new password |
POST | /api/auth/reset-password/verify-email | Verify an email verification code during a password reset |
POST | /api/auth/reset-password/verify-2fa | Verify a two-factor authentication code during a password reset |
POST | /api/auth/reset-password/verify-recovery-code | Verify a recovery code during a password reset |
GET | /api/auth/oauth2/github | Handle the GitHub OAuth callback |
GET | /api/auth/oauth2/google | Handle the Google OAuth callback |
GET | /api/auth/current-user | Return the currently signed-in user |
In production, the middlewares configuration in src/core/services/auth/const.ts loads request-blocking or rate-limiting middleware for endpoints such as sign-in, signup, verification codes, and password resets. Each authentication operation's configuration determines which middleware it uses.
/api/account
These endpoints let signed-in users manage their profile, security settings, products, payments, affiliate participation, and in-app notifications.
Profile and security
| Method | Path | Purpose |
|---|---|---|
POST | /api/account/profile | Update profile information such as the user's name |
GET | /api/account/profile/email-verification | Check verification status for an email address change |
POST | /api/account/profile/send-update-email | Send the verification code required to change an email address |
POST | /api/account/security/initiate-2fa | Start two-factor authentication setup |
POST | /api/account/security/enable-2fa | Enable two-factor authentication |
POST | /api/account/security/disable-2fa | Disable two-factor authentication |
POST | /api/account/security/regenerate-recovery-codes | Regenerate recovery codes |
GET | /api/account/security/delete-account | Retrieve information required to delete the account |
POST | /api/account/security/delete-account | Delete the current account |
Products, payments, and menus
| Method | Path | Purpose |
|---|---|---|
GET | /api/account/products | Return product information visible to the current user |
GET | /api/account/payments | Return the current user's purchases and subscriptions |
GET | /api/account/menu-indicators | Return indicator counts for the account menu |
Affiliate program
| Method | Path | Purpose |
|---|---|---|
GET | /api/account/affiliate | Return the current user's affiliate overview |
GET | /api/account/affiliate/commission-summary | Return a commission summary |
GET | /api/account/affiliate/invalid-commissions | Return commissions excluded from settlement |
POST | /api/account/affiliate/email-verification | Verify the email address to enable affiliate participation |
POST | /api/account/affiliate/enable | Enable affiliate participation |
GET | /api/account/affiliate/payout-profile | Read payout details |
POST | /api/account/affiliate/payout-profile | Save payout details |
In-app notifications
| Method | Path | Purpose |
|---|---|---|
GET | /api/account/notifications | Return the current user's notifications |
POST | /api/account/notifications/read | Mark notifications as read |
POST | /api/account/notifications/:notificationId/open | Record that a notification was opened |
Payments, support tickets, and newsletter subscriptions
| Method | Path | Purpose |
|---|---|---|
POST | /api/payments/checkout/:productId/:planId | Create a checkout session |
POST | /api/payments/:provider/billing | Create a link to the payment provider's billing portal |
POST | /api/webhooks/:provider | Receive payment provider webhooks |
POST | /api/ticket | Create a support ticket |
GET | /api/ticket/:key | Retrieve a support ticket by its access key |
POST | /api/ticket/:key/reply | Reply to a support ticket |
POST | /api/ticket/:key/close | Close a support ticket |
POST | /api/newsletter/subscriptions | Subscribe to the mailing list |
Webhooks do not require a signed-in browser session, but they must pass signature verification for the corresponding payment provider. The available values for :provider depend on the payment providers enabled in config/payment.ts.
/api/analytics/collect
| Method | Path | Purpose |
|---|---|---|
POST | /api/analytics/collect | Receive first-party analytics data |
This route is registered only when analytics.enabled is true in config/deploy.ts. When analytics is disabled, requests to this path return 404.
/oauth
| Method | Path | Purpose |
|---|---|---|
POST | /oauth/token | Exchange an authorization code or refresh a token |
POST | /oauth/token/revoke | Revoke a token |
POST | /oauth/authorize/consent | Approve an authorization request |
POST | /oauth/authorize/dismiss | Deny an authorization request |
GET | /oauth/current-user | Return the user information used by the current OAuth authorization page |
These endpoints belong to the default template's built-in OAuth 2.0 service. OAuth clients, authorization codes, and tokens are stored in oauth_client, oauth_auth_code, and oauth_token, respectively.
/api/dashboard
The entire dashboard route group first runs the requireDashboardAdmin check. Users who do not pass this administrator check cannot access the endpoints below.
Users, roles, and entitlements
| Path prefix | Supported operations |
|---|---|
/api/dashboard/users | List, search, and view users, disable or enable users, soft-delete users, and revoke sessions |
/api/dashboard/roles | List, create, enable, disable, and revoke roles |
/api/dashboard/entitlements | List, create, adjust, enable, and disable entitlements, and refresh subscription cycles |
/api/dashboard/entitlement-events | Query entitlement quota events |
Payments and OAuth clients
| Path prefix | Supported operations |
|---|---|
/api/dashboard/payments/subscriptions | List subscriptions and view subscription details |
/api/dashboard/payments/purchases | List one-time purchases and view purchase details |
/api/dashboard/oauth-clients | List, create, edit, enable, disable, and delete OAuth clients, and regenerate client secrets |
Reaction, support tickets, and logs
| Path prefix | Supported operations |
|---|---|
/api/dashboard/reaction/events | List Event executions and view execution details |
/api/dashboard/reaction/commands | List Command executions, view execution details, and retry manually |
/api/dashboard/tickets | Support ticket lists, details, replies, message editing, hiding, unhiding, and status updates |
/api/dashboard/logger/system | Query system logs |
/api/dashboard/logger/audit | Query audit logs |
/api/dashboard/logger/alert | Query alert logs |
Statistics and affiliate program
| Path prefix | Supported operations |
|---|---|
/api/dashboard/stats | Dashboard statistics for users, subscriptions, support tickets, Reaction executions, and logs |
/api/dashboard/analytics | Traffic overview, events, sessions, performance, funnels, filter options, and client IP addresses |
/api/dashboard/affiliates/users | List affiliates, view details and commissions, and disable or restore affiliates |
/api/dashboard/affiliates/payouts | List monthly settlements, view overviews, commissions, and payout records, and recalculate summaries |
Dashboard analytics queries and frontend data collection share the analytics.enabled switch. When analytics is disabled, query endpoints under /api/dashboard/analytics are not registered.
Notifications
| Path prefix | Supported operations |
|---|---|
/api/dashboard/notifications | List and create notifications, view details, and update status |
Source locations
| Content | Location |
|---|---|
| Main API entry point | src/api/routes.ts |
| Authentication actions and paths | src/core/services/auth/const.ts, src/core/services/auth/routes.tsx |
| Account endpoints | src/api/account/ |
| Dashboard endpoints | src/api/dashboard/ |
| Payment endpoints | src/api/payments/ |
| OAuth 2.0 service | src/api/oauth2-server/ |
| Request parameter validation | schema.ts or route files in each endpoint directory |