Orochia
Documentation
GitHub
For developers

Every HTTP endpoint of the Orochia web app with the access rule that guards it, and the database tables — generated from the code.

Orochia API Reference

Generated from code by scripts/generate-docs.mjs — do not hand-edit.

Endpoints (70)

MethodPathAccessSummary
GET/api/admin/creatorssession · ADMINCreator accounts with their verification state; ?verified=false lists the review queue.
PATCH/api/admin/creators/[id]session · ADMINRecords the outcome of a creator's 18 U.S.C. § 2257 review.
GET/api/admin/documentssession · ADMINA creator's 2257 document (?ref=private/documents/<uuid>.<ext>), for operators only; never cached.
GET/api/admin/overviewsession · ADMINOperator overview: money, catalogue and the three queues that need a human.
GET/api/admin/payoutssession · ADMINPayout requests with their creator; ?status= filters.
PATCH/api/admin/payouts/[id]session · ADMINAdvances a payout.
GET/api/admin/reportssession · ADMINContent reports, newest first; ?status= filters.
PATCH/api/admin/reports/[id]session · ADMINMoves a report through triage (open → in review → resolved).
GET/api/admin/userssession · ADMINEvery account (filter by ?role=, ?suspended=, ?q=): role, verification and suspension state.
PATCH/api/admin/users/[id]session · ADMINSuspends an account (it can no longer sign in, and its open sessions are refused on their next request), reinstates it, or changes its role.
GET/api/admin/videossession · ADMINThe catalogue for moderation: every video with its creator, state and open reports; ?state=removed lists takedowns.
PATCH/api/admin/videos/[id]session · ADMINTakes a video down (DMCA, terms, a confirmed report) with a recorded reason, or restores it.
POST/api/auth/forgot-passwordpublicE-mails a password-reset link (1 h) to the address, if an active account uses it.
POST/api/auth/loginpublicPassword login.
POST/api/auth/logoutpublic—
GET/api/auth/mepublicThe signed-in account (with whether its e-mail is verified), or user: null.
POST/api/auth/registerpublicCreates a member or creator account (never an administrator), signs it in and e-mails the link that verifies its address — until then the account can do nothing else.
POST/api/auth/resend-verificationpublicE-mails a new verification link to the signed-in account (the previous link stops working).
POST/api/auth/reset-passwordpublicSets a new password with the link's one-time token (1 h).
POST/api/auth/verify-emailpublicVerifies an e-mail address with the link's one-time token (48 h); refreshes the session of that account.
GET/api/bunny/analyticssession · ADMINCatalogue statistics for administrators, from the database.
POST/api/contactssession · MEMBER / CREATOR / ADMINSends a contact request (accepted at once when the other person already asked).
DELETE/api/contacts/[id]session · MEMBER / CREATOR / ADMINRemoves a contact or withdraws a request (either side).
PATCH/api/contacts/[id]session · MEMBER / CREATOR / ADMINAccepts or rejects a request addressed to you, or blocks the other person.
GET/api/creator/payoutssession · CREATORThe signed-in creator's balance, lifetime earnings and payout history — from the ledger.
POST/api/creator/payoutssession · CREATORRequests a payout; balances are checked and reserved atomically (requestPayout).
GET/api/creators/[username]public · session-awareA creator's public page: profile, videos, the collections you may open and, signed in, how you relate to them.
DELETE/api/creators/[username]/followsession · MEMBER / CREATOR / ADMINUnfollows a creator.
POST/api/creators/[username]/followsession · MEMBER / CREATOR / ADMINFollows a creator; the follow stays PENDING until the creator approves it.
GET/api/feedpublicThe public feed and the explore search (?q=, ?tag=, paginated); with the featured creator and popular tags.
GET/api/healthpublic—
POST/api/legal/reportpublic · session-awareContent reports.
GET/api/me/dashboardsession · ADMIN / CREATOR / MEMBER—
PATCH/api/me/followers/[id]session · CREATORA creator approves a follower (opening followers-only videos to them) or removes them.
GET/api/me/listssession · MEMBER / CREATOR / ADMINYour reusable audience lists (private to you), with their size.
POST/api/me/listssession · MEMBER / CREATOR / ADMINCreates an audience list (names are unique per account).
DELETE/api/me/lists/[id]session · MEMBER / CREATOR / ADMINDeletes one of your lists; the videos and collections it opened close to its members.
PATCH/api/me/lists/[id]session · MEMBER / CREATOR / ADMINRenames one of your lists.
DELETE/api/me/lists/[id]/memberssession · MEMBER / CREATOR / ADMINRemoves someone from one of your lists (?userId=): what the list opened closes to them.
GET/api/me/lists/[id]/memberssession · MEMBER / CREATOR / ADMINThe people in one of your lists.
POST/api/me/lists/[id]/memberssession · MEMBER / CREATOR / ADMINAdds an account to one of your lists by username (idempotent; the list stays private).
GET/api/me/networksession · MEMBER / CREATOR / ADMINYour followers, the creators you follow, your contacts and pending requests.
PUT/api/me/profilesession · ADMIN / CREATOR / MEMBERUpdates the signed-in user's own profile.
GET/api/metricsbearer tokenPrometheus metrics, behind a bearer token (METRICS_AUTH_TOKEN).
GET/api/payments/gatewayspublicThe gateways a buyer can pay through on this deployment.
GET/api/platform/treasurysession · ADMINPlatform revenue, computed from the ledger only (administrators).
GET/api/playlistssession · MEMBER / CREATOR / ADMINYour playlists, most recently changed first.
POST/api/playlistssession · MEMBER / CREATOR / ADMINCreates a playlist.
DELETE/api/playlists/[id]session · MEMBER / CREATOR / ADMINDeletes a playlist (owner only).
GET/api/playlists/[id]public · session-awareA collection and its videos, for a viewer its permission admits (others get a 404).
PATCH/api/playlists/[id]session · MEMBER / CREATOR / ADMINRenames a collection, edits its description or who may open it (owner only).
DELETE/api/playlists/[id]/itemssession · MEMBER / CREATOR / ADMINRemoves a video from a playlist (owner only).
POST/api/playlists/[id]/itemssession · MEMBER / CREATOR / ADMINAdds a video at the end of a playlist (owner only, idempotent).
GET/api/playlists/sharedsession · MEMBER / CREATOR / ADMINCollections other accounts invited you to.
GET/api/searchpublic—
POST/api/uploadssession · role depends on the requestStores an avatar (any account), a thumbnail or a 2257 document (creators); size and type checked per kind.
DELETE/api/videos/[id]session · CREATORThe creator deletes their video.
PATCH/api/videos/[id]session · CREATORThe creator edits their video: title, description, visibility, unlock price, tags, comments open.
GET/api/videos/[id]/commentspublic · session-awareThe comments of a video you may watch, oldest first; removed ones keep their place without text.
POST/api/videos/[id]/commentssession · MEMBER / CREATOR / ADMINComments on a video you may watch, or replies to one of its comments.
DELETE/api/videos/[id]/comments/[commentId]session · MEMBER / CREATOR / ADMINRemoves a comment: its author, the video's creator or an operator.
GET/api/videos/[id]/detailspublic · session-awareA video's public metadata and figures (and whether you liked it); the stream is only served by /stream.
DELETE/api/videos/[id]/likesession · MEMBER / CREATOR / ADMINRemoves your like (idempotent).
POST/api/videos/[id]/likesession · MEMBER / CREATOR / ADMINLikes a video you may watch (idempotent).
POST/api/videos/[id]/sharespublic · session-awareCounts a share of a video you may watch; the shared link still enforces the video's access.
GET/api/videos/[id]/streampublic · session-awareAuthorises a viewer and returns a short-lived signed HLS URL (AGENTS.md §2.A).
POST/api/videos/create-upload-sessionpublic · session-aware—
POST/api/videos/unlock-videosession · MEMBER / CREATOR / ADMINStarts the purchase of a video unlock.
POST/api/webhooks/bunnysigned webhookBunny Stream encoding events (https://bunny.net/docs/stream/webhooks), signed v1 with the library's Read-Only API key (BUNNY_WEBHOOK_SECRET).
POST/api/webhooks/payments/[gateway]signed webhookGateway payment notifications.

Database tables (23)

TableDrizzle exportDefined in
audience_listsaudienceListspackages/db/src/schema/audiences.ts
audience_list_membersaudienceListMemberspackages/db/src/schema/audiences.ts
video_viewersvideoViewerspackages/db/src/schema/audiences.ts
video_audience_listsvideoAudienceListspackages/db/src/schema/audiences.ts
playlist_audience_listsplaylistAudienceListspackages/db/src/schema/audiences.ts
auth_tokensauthTokenspackages/db/src/schema/auth-tokens.ts
compliance_reportscomplianceReportspackages/db/src/schema/compliance.ts
contactscontactspackages/db/src/schema/contacts.ts
followsfollowspackages/db/src/schema/contacts.ts
video_viewsvideoViewspackages/db/src/schema/engagement.ts
video_likesvideoLikespackages/db/src/schema/engagement.ts
video_commentsvideoCommentspackages/db/src/schema/engagement.ts
video_sharesvideoSharespackages/db/src/schema/engagement.ts
tips_ledgertipsLedgerpackages/db/src/schema/ledger.ts
payment_intentspaymentIntentspackages/db/src/schema/ledger.ts
payout_requestspayoutRequestspackages/db/src/schema/ledger.ts
playlistsplaylistspackages/db/src/schema/playlists.ts
playlist_itemsplaylistItemspackages/db/src/schema/playlists.ts
playlist_membersplaylistMemberspackages/db/src/schema/playlists.ts
usersuserspackages/db/src/schema/users.ts
profilesprofilespackages/db/src/schema/users.ts
videosvideospackages/db/src/schema/videos.ts
video_access_grantsvideoAccessGrantspackages/db/src/schema/videos.ts