Documentation
API

API Reference

Pour les développeurs

Every HTTP endpoint of the Orochia web app with the access rule that guards it, and the database tables — generated from the code.

Generated from code by scripts/generate-docs.mjs — do not hand-edit.

Endpoints (153)

MethodPathAccessSummary
GET/api/admin/auctionssession · ADMINEvery auction for operators (latest first, optionally by status): video, creator, price, bids, timing, outcome.
DELETE/api/admin/auctions/[id]session · ADMINCancels an auction that is open or awaiting its decision, with a recorded reason; the leading bid is released.
GET/api/admin/creatorssession · ADMINCreator accounts with their verification state; ?verified=false lists the review queue.
PATCH/api/admin/creators/[id]session · ADMINRecords the outcome of a creator's 18 U.S.C. § 2257 review.
GET/api/admin/documentssession · ADMINA creator's 2257 document (?ref=private/documents/<uuid>.<ext>), for operators only; never cached.
GET/api/admin/overviewsession · ADMINOperator overview: money, catalogue and the three queues that need a human.
GET/api/admin/payoutssession · ADMINPayout requests with their creator; ?status= filters.
PATCH/api/admin/payouts/[id]session · ADMINAdvances a payout.
GET/api/admin/platformsession · ADMINThe platform for operators: environment, database (size, rows per table), migration history, whether a reset is allowed.
GET/api/admin/platform/backupssession · ADMINThe database backups kept in private storage, newest first.
POST/api/admin/platform/backupssession · ADMINBacks the whole database up now (gzipped JSON of every table, in private storage).
DELETE/api/admin/platform/backups/[name]session · ADMINDeletes a backup from private storage.
GET/api/admin/platform/backups/[name]session · ADMINDownloads a backup file (?download=1), or describes it: tables, rows, migrations.
POST/api/admin/platform/resetsession · ADMINFactory reset: backs the database up first (unless asked not to), wipes it and rebuilds it from the migrations — development deployments only (OROCHIA_ALLOW_DATABASE_RESET, never the indexed production), after the operator typed “reset <database>”. The operator and the owner are kept.
GET/api/admin/reportssession · ADMINContent reports, newest first; ?status= filters.
PATCH/api/admin/reports/[id]session · ADMINMoves a report through triage (open → in review → resolved).
GET/api/admin/userssession · ADMINEvery account (filter by ?role=, ?suspended=, ?q=): role, verification and suspension state.
PATCH/api/admin/users/[id]session · ADMINSuspends an account (it can no longer sign in, and its open sessions are refused on their next request; its open auctions are cancelled and their bids released), reinstates it, or changes its role.
GET/api/admin/videossession · ADMINThe catalogue for moderation: every video with its creator, state and open reports; ?state=removed lists takedowns.
PATCH/api/admin/videos/[id]session · ADMINTakes a video down (DMCA, terms, a confirmed report) with a recorded reason — cancelling its auction — or restores it.
GET/api/auctionspublic · session-awareLists auctions by tab: open, upcoming, ended (sold), bidding (yours) or selling (your own).
POST/api/auctionssession · CREATORPuts one of the creator's ready videos up for auction (start, end, starting price, rights, how it ends).
DELETE/api/auctions/[id]session · CREATORThe creator cancels their auction while nobody has bid; the video gets its previous visibility back.
GET/api/auctions/[id]public · session-awareAn auction as the viewer sees it: price, minimum next bid, timing, recent bids (aliases), and their own standing.
POST/api/auctions/[id]/bidssession · MEMBER / CREATOR / ADMINPlaces a bid in Orochia credits; they are held while the bid leads and released when it is outbid.
POST/api/auctions/[id]/decisionsession · CREATORThe creator accepts the best bid (the video is sold to its bidder) or declines it (the credits go back).
GET/api/auctions/[id]/streampublicServer-Sent Events of an auction: each bid (amount, alias, new end) and every change of state.
POST/api/auth/forgot-passwordpublicE-mails a password-reset link (1 h) to the address, if an active account uses it.
POST/api/auth/loginpublicPassword login — a session cookie for the browser, a bearer token for a native app.
POST/api/auth/logoutpublic—
GET/api/auth/mepublicThe signed-in account (with whether its e-mail is verified), or user: null.
GET/api/auth/oauth/[provider]/callbackpublicThe provider's redirect: checks the state, exchanges the code, then signs in (linked account or same verified address) or sends a new person to complete their account.
GET/api/auth/oauth/[provider]/startpublicSends the browser to the provider's consent page (state + PKCE kept in a signed 10-minute cookie).
POST/api/auth/oauth/completepublicCreates the account of a new Google / Facebook sign-in after the person gives a date of birth (18+), certifies it and accepts the terms.
GET/api/auth/oauth/pendingpublicThe provider sign-in waiting to become an account: what the completion form can prefill.
GET/api/auth/providerspublicThe sign-in providers this deployment offers (only those whose keys are configured).
POST/api/auth/registerpublicCreates an account (a member — creators are opened later, never an administrator), signs it in and e-mails the link that verifies its address — until then the account can do nothing else.
POST/api/auth/resend-verificationpublicE-mails a new verification link to the signed-in account (the previous link stops working).
POST/api/auth/reset-passwordpublicSets a new password with the link's one-time token (1 h).
GET/api/auth/usernamepublicWhether a username is free (unique address orochia.com/@username), with a free one suggested when it is not.
POST/api/auth/verify-emailpublicVerifies an e-mail address with the link's one-time token (48 h); refreshes the session of that account.
GET/api/bunny/analyticssession · ADMINCatalogue statistics for administrators, from the database.
GET/api/challengespublic · session-awareLists challenges by tab: open, calls (open calls), done (delivered), inbox (yours to answer or deliver), mine, backing.
POST/api/challengessession · MEMBER / CREATOR / ADMINOpens a challenge: a creator's goal (pledges until the deadline, all or nothing), a request to one creator (the sender's offer is held at once; the creator has three days to answer) or an open call for any creator (the author's pot is held; creators apply and the author picks one).
GET/api/challenges/[id]public · session-awareA challenge as the viewer sees it: progress, deadlines, backers (aliases), applications and what the viewer may do.
POST/api/challenges/[id]/answersession · CREATORThe creator a request was sent to accepts it (and must deliver in time) or declines it (every pledge comes back).
POST/api/challenges/[id]/applicationssession · CREATORA verified creator applies to take an open call, with a short note for its author.
POST/api/challenges/[id]/assignsession · MEMBER / CREATOR / ADMINThe author of an open call picks one applicant, who now has the delivery window to make it.
POST/api/challenges/[id]/cancelsession · MEMBER / CREATOR / ADMINThe author withdraws an open challenge (a goal, a request not answered yet, an open call): every pledge comes back.
GET/api/challenges/[id]/deliverysession · CREATORWhat the creator can deliver: their ready videos not used elsewhere, or the stories posted since they committed.
POST/api/challenges/[id]/deliverysession · CREATORThe creator delivers a video or a story: the backers' pledges are paid and they can watch it.
POST/api/challenges/[id]/pledgessession · MEMBER / CREATOR / ADMINPledges Orochia credits to an open challenge; they are held until it is delivered and come back if it is not.
POST/api/challenges/[id]/startsession · CREATORA goal's creator starts it as soon as the goal is reached (pledging stops; the delivery window begins).
GET/api/challenges/[id]/streampublicServer-Sent Events of a challenge: each pledge (amount, alias, new total) and every change of state.
POST/api/contactssession · MEMBER / CREATOR / ADMINSends a contact request (accepted at once when the other person already asked).
DELETE/api/contacts/[id]session · MEMBER / CREATOR / ADMINRemoves a contact or withdraws a request (either side).
PATCH/api/contacts/[id]session · MEMBER / CREATOR / ADMINAccepts or rejects a request addressed to you, or blocks the other person.
GET/api/conversationssession · ADMIN / CREATOR / MEMBERLists the signed-in user's active direct conversations.
POST/api/conversationssession · ADMIN / CREATOR / MEMBERStarts or retrieves a conversation with a specified user.
GET/api/conversations/[id]/messagessession · ADMIN / CREATOR / MEMBERLists messages in a conversation and marks unread messages as read.
POST/api/conversations/[id]/messagessession · ADMIN / CREATOR / MEMBERSends a direct message in a conversation.
GET/api/conversations/streampublicRealtime Server-Sent Events (SSE) stream for instant direct messages and notifications.
GET/api/creator/earningssession · CREATOR / ADMINYour earnings for a period (?period=30d
GET/api/creator/earnings/exportsession · CREATOR / ADMINDownloads your earnings as CSV (?kind=transactions
GET/api/creator/payoutssession · CREATOR / ADMINThe signed-in creator's balance, lifetime earnings and payout history — from the ledger.
POST/api/creator/payoutssession · CREATOR / ADMINRequests a payout to your saved payout account (an encrypted snapshot is kept); balance checked and reserved atomically.
GET/api/creators/[username]public · session-awareA creator's public page: profile, videos, the collections you may open and, signed in, how you relate to them.
DELETE/api/creators/[username]/followsession · MEMBER / CREATOR / ADMINUnfollows a creator.
POST/api/creators/[username]/followsession · MEMBER / CREATOR / ADMINFollows a creator; the follow stays PENDING until the creator approves it.
GET/api/feedpublicThe public feed and the explore search (?q=, ?tag=, paginated); with the featured creator and popular tags.
GET/api/healthpublic—
POST/api/legal/reportpublic · session-awareContent reports.
POST/api/me/become-creatorsession · MEMBER / CREATOR / ADMINOpens a creator space for a member: the account becomes CREATOR, pending its 18 U.S.C. § 2257 review (uploads open once an operator verifies it).
POST/api/me/birth-datesession · ADMIN / CREATOR / MEMBERRecords your date of birth (18+) when the account has none yet; once set it cannot be changed here.
GET/api/me/blockssession · ADMIN / CREATOR / MEMBERLists the accounts blocked by the signed-in user.
GET/api/me/dashboardsession · ADMIN / CREATOR / MEMBER—
DELETE/api/me/devicessession · MEMBER / CREATOR / ADMINForgets one of the account's phones (sign-out, notifications turned off on the device).
POST/api/me/devicessession · MEMBER / CREATOR / ADMINRegisters the phone the app runs on for push notifications (an Expo push token, moved if it served another account).
GET/api/me/draftssession · CREATOR / ADMINYour editor drafts (newest first), with a short-lived link to each original clip; expired ones are removed.
POST/api/me/draftssession · CREATOR / ADMINKeeps an edit as a draft: records its settings and returns a Tus session to send the original clip straight to Bunny.
DELETE/api/me/drafts/[id]session · CREATOR / ADMINDeletes one of your drafts with its clip and music.
GET/api/me/drafts/[id]session · CREATOR / ADMINOne of your drafts, with a short-lived link to its original clip.
PATCH/api/me/drafts/[id]session · CREATOR / ADMINSaves new edit settings or form values on a draft (the clip is not sent again); it is kept longer.
DELETE/api/me/drafts/[id]/musicsession · CREATOR / ADMINRemoves the music track of a draft.
GET/api/me/drafts/[id]/musicsession · CREATOR / ADMINThe music track of one of your drafts (private: served to you only).
PUT/api/me/drafts/[id]/musicsession · CREATOR / ADMINKeeps (or replaces) the music track of a draft — MP3, M4A, AAC, WAV or OGG up to 25 MB.
POST/api/me/drafts/[id]/uploadedsession · CREATOR / ADMINTells that a draft's original clip is fully sent, so it can be opened again before Bunny finishes processing.
PATCH/api/me/followers/[id]session · CREATORA creator approves a follower (opening followers-only videos to them) or removes them.
GET/api/me/identitiessession · ADMIN / CREATOR / MEMBERLists the external OAuth providers linked to the signed-in account.
DELETE/api/me/identities/[id]session · ADMIN / CREATOR / MEMBERUnlinks a connected OAuth provider identity from the signed-in account.
GET/api/me/invitationssession · ADMIN / CREATOR / MEMBERLists invitations sent by the signed-in user.
POST/api/me/invitationssession · ADMIN / CREATOR / MEMBERSends an invitation to join Orochia to a friend or collaborator.
GET/api/me/listssession · MEMBER / CREATOR / ADMINYour reusable audience lists (private to you), with their size.
POST/api/me/listssession · MEMBER / CREATOR / ADMINCreates an audience list (names are unique per account).
DELETE/api/me/lists/[id]session · MEMBER / CREATOR / ADMINDeletes one of your lists; the videos and collections it opened close to its members.
PATCH/api/me/lists/[id]session · MEMBER / CREATOR / ADMINRenames one of your lists.
DELETE/api/me/lists/[id]/memberssession · MEMBER / CREATOR / ADMINRemoves someone from one of your lists (?userId=): what the list opened closes to them.
GET/api/me/lists/[id]/memberssession · MEMBER / CREATOR / ADMINThe people in one of your lists.
POST/api/me/lists/[id]/memberssession · MEMBER / CREATOR / ADMINAdds an account to one of your lists by username (idempotent; the list stays private).
GET/api/me/networksession · MEMBER / CREATOR / ADMINYour followers, the creators you follow, your contacts and pending requests.
GET/api/me/notificationssession · MEMBER / CREATOR / ADMINYour notifications, newest first, 25 at a time (before = an ISO date to page back), with the unread count.
POST/api/me/notificationssession · MEMBER / CREATOR / ADMINMarks notifications read: the ones listed, or all of them.
GET/api/me/payout-accountsession · CREATOR / ADMINWhere your earnings are sent — shown masked (e.g.
PUT/api/me/payout-accountsession · CREATOR / ADMINSaves (or replaces) where your earnings are sent; the details are checked and encrypted at rest.
GET/api/me/profilesession · ADMIN / CREATOR / MEMBERReads the signed-in user's own profile and settings (private fields included: e-mail, date of birth).
PUT/api/me/profilesession · ADMIN / CREATOR / MEMBERUpdates the signed-in user's own profile and preferences (only the fields sent).
GET/api/me/storiessession · CREATOR / ADMINYour stories of the last 30 days — up, encoding or expired — with their figures.
GET/api/me/walletsession · MEMBER / CREATOR / ADMINYour Orochia credits: balance (and what is held behind your leading bids and challenge pledges), the packs you can buy, how you can pay for them, and your history.
POST/api/me/wallet/topupssession · MEMBER / CREATOR / ADMINBuys credits: returns the gateway's hosted checkout (card, Apple Pay, Google Pay — card details never reach Orochia); the gateway's signed webhook adds the credits.
GET/api/metricsbearer tokenPrometheus metrics, behind a bearer token (METRICS_AUTH_TOKEN).
GET/api/payments/gatewayspublicThe ways a buyer can pay on this deployment: credits (the wallet), then the external gateways.
GET/api/platform/treasurysession · ADMINPlatform revenue, computed from the ledger only (administrators).
GET/api/playlistssession · MEMBER / CREATOR / ADMINYour playlists, most recently changed first.
POST/api/playlistssession · MEMBER / CREATOR / ADMINCreates a playlist.
DELETE/api/playlists/[id]session · MEMBER / CREATOR / ADMINDeletes a playlist (owner only).
GET/api/playlists/[id]public · session-awareA collection and its videos, for a viewer its permission admits (others get a 404).
PATCH/api/playlists/[id]session · MEMBER / CREATOR / ADMINRenames a collection, edits its description or who may open it (owner only).
DELETE/api/playlists/[id]/itemssession · MEMBER / CREATOR / ADMINRemoves a video from a playlist (owner only).
POST/api/playlists/[id]/itemssession · MEMBER / CREATOR / ADMINAdds a video at the end of a playlist (owner only, idempotent).
GET/api/playlists/sharedsession · MEMBER / CREATOR / ADMINCollections other accounts invited you to.
GET/api/reference/content-ratingspublicReference content classifications and age ratings (Kids Safe, General, Teens, Mature, Adult).
GET/api/reference/presetspublicDefault avatar and banner presets users can choose without uploading custom files.
GET/api/searchpublic—
GET/api/storiespublic · session-awareThe stories rail: one ring per creator with current stories you may see (yours first, then unseen), signed for you — ?creator=&lt;username&gt; keeps that creator's ring only (a profile's story ring); with ?pending=1, your own video stories too while they are processing (state).
POST/api/storiessession · CREATOR / ADMINPublishes an image story (24 h) from an image stored by /api/uploads (category "stories"); verified creators only.
DELETE/api/stories/[id]session · CREATOR / ADMINWithdraws a story: its creator or an operator.
PATCH/api/stories/[id]session · CREATOR / ADMINChanges who sees a live story (its creator only; a story delivered for a challenge keeps its backers).
GET/api/stories/[id]/insightssession · CREATOR / ADMINA story's activity for its creator: views (accounts named, visitors counted), likes, tips and who sent them.
DELETE/api/stories/[id]/likesession · MEMBER / CREATOR / ADMINRemoves your like (idempotent).
POST/api/stories/[id]/likesession · MEMBER / CREATOR / ADMINLikes a story you may see (idempotent).
POST/api/stories/[id]/replysession · MEMBER / CREATOR / ADMINAnswers a story privately: a direct message to its creator, linked to the story (blocks and message privacy apply).
POST/api/stories/[id]/tipsession · MEMBER / CREATOR / ADMINTips a creator from one of their stories.
POST/api/stories/[id]/viewpublic · session-awareCounts a view of a story you may see — once per viewer, never the creator's own.
POST/api/stories/upload-sessionsession · CREATOR / ADMINStarts a video story: records it and returns a Tus session straight to Bunny (stories collection).
POST/api/uploadssession · role depends on the requestStores an avatar or a profile banner (any account), a thumbnail, a story image or a 2257 document (creators); size and type checked per kind.
DELETE/api/users/[username]/blocksession · ADMIN / CREATOR / MEMBERUnblocks a previously blocked user.
POST/api/users/[username]/blocksession · ADMIN / CREATOR / MEMBERBlocks or unblocks a user: toggles block state on POST.
DELETE/api/videos/[id]session · CREATORThe creator deletes their video (refused while it is in an auction, and for a video its challenge's backers paid for).
PATCH/api/videos/[id]session · CREATORThe creator edits their video (an auctioned or challenge video keeps its audience): title, description, visibility, unlock price, tags, comments open.
GET/api/videos/[id]/auctionpublic · session-awareThe auction a video is in (open, awaiting its decision or sold), as the viewer sees it; null when there is none.
GET/api/videos/[id]/commentspublic · session-awareThe comments of a video you may watch, oldest first; removed ones keep their place without text.
POST/api/videos/[id]/commentssession · MEMBER / CREATOR / ADMINComments on a video you may watch, or replies to one of its comments.
DELETE/api/videos/[id]/comments/[commentId]session · MEMBER / CREATOR / ADMINRemoves a comment: its author, the video's creator or an operator.
GET/api/videos/[id]/detailspublic · session-awareA video's public metadata and figures (and whether you liked it); the stream is only served by /stream.
GET/api/videos/[id]/downloadsession · MEMBER / CREATOR / ADMINA five-minute signed link to the video's MP4 file, for its author and for a buyer whose grant includes downloading.
DELETE/api/videos/[id]/likesession · MEMBER / CREATOR / ADMINRemoves your like (idempotent).
POST/api/videos/[id]/likesession · MEMBER / CREATOR / ADMINLikes a video you may watch (idempotent).
POST/api/videos/[id]/sharespublic · session-awareCounts a share of a video you may watch; the shared link still enforces the video's access.
GET/api/videos/[id]/streampublic · session-awareAuthorises a viewer and returns a short-lived signed HLS URL (AGENTS.md §2.A).
POST/api/videos/create-upload-sessionpublic · session-aware—
POST/api/videos/unlock-videosession · MEMBER / CREATOR / ADMINStarts the purchase of a video unlock.
POST/api/webhooks/bunnysigned webhookBunny Stream encoding events (https://bunny.net/docs/stream/webhooks), signed v1 with the library's Read-Only API key (BUNNY_WEBHOOK_SECRET).
POST/api/webhooks/payments/[gateway]signed webhookGateway payment notifications.

Database tables (43)

TableDrizzle exportDefined in
auctionsauctionspackages/db/src/schema/auctions.ts
auction_bidsauctionBidspackages/db/src/schema/auctions.ts
audience_listsaudienceListspackages/db/src/schema/audiences.ts
audience_list_membersaudienceListMemberspackages/db/src/schema/audiences.ts
video_viewersvideoViewerspackages/db/src/schema/audiences.ts
video_audience_listsvideoAudienceListspackages/db/src/schema/audiences.ts
playlist_audience_listsplaylistAudienceListspackages/db/src/schema/audiences.ts
auth_identitiesauthIdentitiespackages/db/src/schema/auth-identities.ts
auth_tokensauthTokenspackages/db/src/schema/auth-tokens.ts
challengeschallengespackages/db/src/schema/challenges.ts
challenge_pledgeschallengePledgespackages/db/src/schema/challenges.ts
challenge_applicationschallengeApplicationspackages/db/src/schema/challenges.ts
compliance_reportscomplianceReportspackages/db/src/schema/compliance.ts
contactscontactspackages/db/src/schema/contacts.ts
followsfollowspackages/db/src/schema/contacts.ts
video_draftsvideoDraftspackages/db/src/schema/drafts.ts
video_viewsvideoViewspackages/db/src/schema/engagement.ts
video_likesvideoLikespackages/db/src/schema/engagement.ts
video_commentsvideoCommentspackages/db/src/schema/engagement.ts
video_sharesvideoSharespackages/db/src/schema/engagement.ts
user_invitationsuserInvitationspackages/db/src/schema/invitations.ts
tips_ledgertipsLedgerpackages/db/src/schema/ledger.ts
payment_intentspaymentIntentspackages/db/src/schema/ledger.ts
payout_requestspayoutRequestspackages/db/src/schema/ledger.ts
conversationsconversationspackages/db/src/schema/messaging.ts
direct_messagesdirectMessagespackages/db/src/schema/messaging.ts
blocked_usersblockedUserspackages/db/src/schema/messaging.ts
notificationsnotificationspackages/db/src/schema/notifications.ts
playlistsplaylistspackages/db/src/schema/playlists.ts
playlist_itemsplaylistItemspackages/db/src/schema/playlists.ts
playlist_membersplaylistMemberspackages/db/src/schema/playlists.ts
push_devicespushDevicespackages/db/src/schema/push.ts
content_ratingscontentRatingspackages/db/src/schema/reference-data.ts
storiesstoriespackages/db/src/schema/stories.ts
story_viewsstoryViewspackages/db/src/schema/stories.ts
story_likesstoryLikespackages/db/src/schema/stories.ts
usersuserspackages/db/src/schema/users.ts
profilesprofilespackages/db/src/schema/users.ts
videosvideospackages/db/src/schema/videos.ts
video_access_grantsvideoAccessGrantspackages/db/src/schema/videos.ts
credit_topupscreditTopupspackages/db/src/schema/wallet.ts
wallet_ledgerwalletLedgerpackages/db/src/schema/wallet.ts
payout_accountspayoutAccountspackages/db/src/schema/wallet.ts

Présentation du produit →

Sur cette page