Skip to main content
One idea at a time

The HTTP route inventory

This table is generated from app.ts by prepare-docs.mjs. Parameter names beginning with a colon stand for a concrete UUID.

MethodPath
GET/health/live
GET/health/ready
GET/metrics
POST/api/webhooks/stripe
POST/api/auth/register
POST/api/auth/login
GET/api/auth/me
POST/api/auth/logout
POST/api/auth/verify-email
POST/api/auth/forgot-password
POST/api/auth/reset-password
GET/api/workspaces
POST/api/workspaces
GET/api/workspaces/:workspaceId
GET/api/workspaces/:workspaceId/members
PATCH/api/workspaces/:workspaceId/members/:userId
DELETE/api/workspaces/:workspaceId/members/:userId
POST/api/workspaces/:workspaceId/invitations
POST/api/invitations/accept
GET/api/workspaces/:workspaceId/projects
POST/api/workspaces/:workspaceId/projects
GET/api/workspaces/:workspaceId/projects/:projectId/tasks
POST/api/workspaces/:workspaceId/projects/:projectId/tasks
PATCH/api/workspaces/:workspaceId/tasks/:taskId
DELETE/api/workspaces/:workspaceId/tasks/:taskId
GET/api/workspaces/:workspaceId/tasks/:taskId/comments
POST/api/workspaces/:workspaceId/tasks/:taskId/comments
GET/api/workspaces/:workspaceId/activity
GET/api/workspaces/:workspaceId/billing
POST/api/workspaces/:workspaceId/billing/checkout
POST/api/workspaces/:workspaceId/billing/portal

Authentication responses contain user and csrfToken fields. Resource responses use a data envelope. List responses contain items and nextCursor when paginated.

Authenticated POST, PATCH, and DELETE requests require X-CSRF-Token. Unsafe browser requests must match APP_ORIGIN. Task creation and checkout require an Idempotency-Key header. Task edits and deletion require expectedVersion.

Workspace roles are checked by the domain function. Members can create and edit tasks and comments. Admins can create projects, invite people, and delete tasks. Owners can also change membership roles and manage billing.

Errors contain error.code, error.message, and requestId. Typical statuses include 400 for invalid input, 401 for an invalid session, 403 for a denied action, 404 for an unavailable tenant resource, 409 for a conflict, 429 for a rate limit, and 503 for an unavailable dependency.

Open the route handlers and exact input schemas.