API endpoints
Being written
This page is being written.
Write an endpoint, and control who may call it.
This page will cover
- Define business endpoints under
/api - Mount webhooks and third-party callbacks at the root
- Every route owns its own authentication and authorization — never rely on another route's
- Keep HTTP concerns separate from domain logic

