API endpoints

Being written

This page is being written.

Write an endpoint, and control who may call it.

This page will cover

  • Define business endpoints under /api
  • Mount webhooks and third-party callbacks at the root
  • Every route owns its own authentication and authorization — never rely on another route's
  • Keep HTTP concerns separate from domain logic