Eternaltwin

Home | /api

/api/v1

The current Eternaltwin API. Every path below is relative to /api/v1.

  • / — server metadata (the API home document).
  • app — the desktop application's release feed.
  • apps — registered applications.
  • archive — archived Dinoparc, Hammerfest and Twinoid data.
  • auth — the authentication context, sign-in and sign-out.
  • captcha — the proof-of-work captcha used by the registration and sign-in forms.
  • clock — the server clock (and, in development, time travel).
  • config — the pieces of the server configuration a client needs.
  • forum — sections, threads, posts and moderation.
  • job — background jobs and tasks. Administrators only.
  • oauth_clients — seeding of system OAuth clients. Internal: requires the Etwin-Internal-Auth header.
  • oauth_consent — data behind the OAuth consent screen. Internal to the website, no stability guarantee.
  • outbound_email — the outbound mail queue. Administrators only.
  • users — user accounts, their links and their sanctions.

Routes served by the same process but outside /api — the backend-for-frontend, the OAuth browser flow and the OpenTelemetry collectors — are listed in Internal endpoints.

Cross-origin requests

The router installs a CORS layer that allows http://localhost:4200 (the Angular development server) with credentials, for the methods GET, HEAD, POST, PUT, PATCH, DELETE and OPTIONS, and the headers Content-Type, Authorization and Accept. Other origins are not allowed by the backend itself; a deployment puts the website and the API behind the same origin instead.